CVE-2025-4561
Last modified
CVE-2025-4561 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The KFOX from KingFor has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privilege to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.. EPSS estimates a 0.57% chance of exploitation in the next 30 days.
Description
The KFOX from KingFor has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privilege to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-4561?
How severe is CVE-2025-4561?
How do I fix CVE-2025-4561?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-45587A stack overflow in the FTP service of Audi UTR 2.0 Universa…7
- CVE-2025-4559The ISOinsight from Netvision has a SQL Injection vulnerabil…9.8
- CVE-2025-4560The ISOinsight from Netvision has a Missing Authentication v…6.9
- CVE-2025-45607An issue in the component /manage/ of itranswarp v2.19 allow…9.8
- CVE-2025-45608Incorrect access control in the /system/user/findUserList AP…7.5
- CVE-2025-45609Incorrect access control in the doFilter function of kob lat…7.5
- CVE-2025-45610Incorrect access control in the component /scheduleLog/info/…7.5
- CVE-2025-45611Incorrect access control in the /user/edit/ component of hop…9.8
- CVE-2025-45612Incorrect access control in xmall v1.1 allows attackers to b…9.8
- CVE-2025-45613Incorrect access control in the component /user/list of Shir…7.5
- CVE-2025-45614Incorrect access control in the component /api/user/manager …7.5
- CVE-2025-45615Incorrect access control in the /admin/ API of yaoqishan v0.…9.8
Are you affected by CVE-2025-4561?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
