Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used.
PUBLISHED5.2CWE-95
Problem type
Affected products
Xspeeder
SXZOS
<= 2025-12-26 - AFFECTED
References
xspeeder.com
https://www.xspeeder.com
pwn.ai
https://pwn.ai/blog/cve-2025-54322-zeroday-unauthenticated-root-rce-affecting-70-000-hosts
GitHub Security Advisories
GHSA-2qm6-vprh-vgfc
Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python...
https://github.com/advisories/GHSA-2qm6-vprh-vgfcXspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used.
From Hacker News
0day unauthenticated RCE affecting 70k devices on the internet found by AIhttps://pwn.ai/blog/cve-2025-54322-zeroday-unauthenticated-root-rce-affecting-70-000-hosts
JSON source
https://cveawg.mitre.org/api/cve/CVE-2025-54322Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2025-54322",
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"dateUpdated": "2025-12-27T13:52:27.648Z",
"dateReserved": "2025-07-20T00:00:00.000Z",
"datePublished": "2025-12-27T00:00:00.000Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre",
"dateUpdated": "2025-12-27T13:52:27.648Z"
},
"descriptions": [
{
"lang": "en",
"value": "Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used."
}
],
"affected": [
{
"vendor": "Xspeeder",
"product": "SXZOS",
"defaultStatus": "unaffected",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "custom",
"lessThanOrEqual": "2025-12-26"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')",
"cweId": "CWE-95",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://www.xspeeder.com"
},
{
"url": "https://pwn.ai/blog/cve-2025-54322-zeroday-unauthenticated-root-rce-affecting-70-000-hosts"
}
],
"metrics": [
{
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"baseScore": 10,
"baseSeverity": "CRITICAL"
}
}
]
}
}
}