CVE-2025-6076
Last modified
CVE-2025-6076 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Partner Software's Partner Software application and Partner Web application do not sanitize files uploaded on the "reports" tab, allowing an authenticated attacker to upload a malicious file and compromise the device. By default, the software runs as SYSTEM, heightening the severity of the vulnerability.. EPSS estimates a 0.66% chance of exploitation in the next 30 days.
Description
Partner Software's Partner Software application and Partner Web application do not sanitize files uploaded on the "reports" tab, allowing an authenticated attacker to upload a malicious file and compromise the device. By default, the software runs as SYSTEM, heightening the severity of the vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-6076?
How severe is CVE-2025-6076?
How do I fix CVE-2025-6076?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-60739Cross Site Request Forgery (CSRF) vulnerability in Ilevia EV…9.6
- CVE-2025-6074Use of Hard-coded Cryptographic Key vulnerability in ABB RMC…6.5
- CVE-2025-60749DLL Hijacking vulnerability in Trimble SketchUp desktop 2025…7.8
- CVE-2025-6075If the value passed to os.path.expandvars() is user-controll…5.5
- CVE-2025-60751GeographicLib 2.5 is vulnerable to Buffer Overflow in GeoCon…7.5
- CVE-2025-60753An issue was discovered in libarchive bsdtar before version …5.5
- CVE-2025-6077Partner Software's Partner Software Product and correspondin…9.8
- CVE-2025-60772Improper authentication in the web-based management interfac…9.8
- CVE-2025-6078Partner Software's Partner Software application and Partner …5.4
- CVE-2025-60781PHP Education Manager v1.0 is vulnerable to Cross Site Scrip…6.1
- CVE-2025-60782PHP Education Manager v1.0 is vulnerable to Cross Site Scrip…5.4
- CVE-2025-60783There is a SQL injection vulnerability in Restaurant Managem…6.5
Are you affected by CVE-2025-6076?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
