CVE-2025-8148
Last modified
CVE-2025-8148 is a medium-severity vulnerability rated 4.2/10 on the CVSS scale. An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their SSH key.. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their SSH key.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fortra | Goanywhere Managed File Transfer | < 7.9.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-8148?
How severe is CVE-2025-8148?
How do I fix CVE-2025-8148?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-8141The Redirection for Contact Form 7 plugin for WordPress is v…8.8
- CVE-2025-8142The Soledad theme for WordPress is vulnerable to Local File …8.8
- CVE-2025-8143The Soledad theme for WordPress is vulnerable to Stored Cros…6.4
- CVE-2025-8145The Redirection for Contact Form 7 plugin for WordPress is v…8.8
- CVE-2025-8146The Qi Addons For Elementor plugin for WordPress is vulnerab…6.4
- CVE-2025-8147The LWSCache plugin for WordPress is vulnerable to unauthori…4.3
- CVE-2025-8149The aThemes Addons for Elementor plugin for WordPress is vul…6.4
- CVE-2025-8150The Events Addon for Elementor plugin for WordPress is vulne…6.4
- CVE-2025-8151The HT Mega – Absolute Addons For Elementor plugin for WordP…4.3
- CVE-2025-8152The WP CTA – Call To Action Plugin, Sticky CTA, Sticky Butto…5.3
- CVE-2025-8153Cross-site Scripting vulnerability in NEC Corporation UNIVER…5.1
- CVE-2025-8154In Webhook API invocations, the component accepts user-suppl…7.5
Are you affected by CVE-2025-8148?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
