Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-14728— Rapid7 Velociraptor Directory Traversal Vulnerability

CVSS 6.8 · Medium EPSS 0.47% · P65
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-14728

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Rapid7 Velociraptor Directory Traversal Vulnerability
Source: NVD (National Vulnerability Database)
Vulnerability Description
Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is written outside the datastore directory. Velociraptor is normally only allowed to write in the datastore directory. The issue occurs due to insufficient sanitization of directory names which end with a ".", only encoding the final "." AS "%2E". Although files can be written to incorrect locations, the containing directory must end with "%2E". This limits the impact of this vulnerability, and prevents it from overwriting critical files.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Rapid7 Velociraptor 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Rapid7 Velociraptor是美国Rapid7公司的一个数字取证与事件响应平台。 Rapid7 Velociraptor 0.75.6之前版本存在安全漏洞,该漏洞源于Linux服务器上目录名清理不足,可能导致目录遍历和文件写入错误位置。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Rapid7Velociraptor 0 ~ 0.75.6 -

II. Public POCs for CVE-2025-14728

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-14728

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2025-14728

No comments yet


Leave a comment