CVE-2025-34300
A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the ciwweb.pl http://ciwweb.pl/  Perl web application. Exploitation allows an unauthenticated attacker can execute arbitrary commands.
- Affected products
- Sawtooth Lighthouse Studio
- Fix
- Available
- CVSS 4.0
- 10.0 CRITICAL
- EPSS
- 78.1% (100th percentile)
- Weakness
- CWE-20, CWE-1336
- NVD status
- Deferred
- Published
- 2025-07-16
- Attack patterns
- CAPEC-242
- Entry point
- hid_javascript query param
- Path
- cgi-bin/ciwweb.pl
CVE-2025-34300 at NVD
5 known exploits for CVE-2025-34300
Proof-of-concept code and exploit modules indexed by Sploitus