susemanager-tftpsync-recv allows arbitrary file creation and deletion due to path traversal
Vulnerability Description
A Path Traversal vulnerability in the tftpsync/add and tftpsync/delete scripts allows a remote attacker on an adjacent network to write or delete files on the filesystem with the privileges of the unprivileged wwwrun user. Although the endpoint is unauthenticated, access is restricted to a list of allowed IP addresses.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-53880
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Paolo Perego of SUSE
More from SUSE
View All →Affected Vendor
SUSE
View all reports →