S4E just found a medium log file scanner
critical·Product Based Web Vulnerabilities·Updated Aug 15, 2025

CVE-2025-34073 Scanner

CVE-2025-34073 Scanner - Remote Code Execution vulnerability in Maltrail

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-34073
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

An unauthenticated command injection vulnerability exists in stamparm/maltrail (Maltrail) versions <=0.54. A remote attacker can execute arbitrary operating system commands via the username parameter in a POST request to the /login endpoint. This occurs due to unsafe handling of user-supplied input passed to subprocess.check_output() in core/http.py, allowing injection of shell metacharacters. Exploitation does not require authentication and commands are executed with the privileges of the Maltrail process.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Maltrailby Stamparm
0
Updated Aug 19, 2026View on NVD →
Detail

Maltrail is a reputable traffic monitoring system used by network administrators to track suspicious activities in network traffic. It is employed across various industries to ensure network security by identifying and responding to potential threats in real time. Organizations from small businesses to large enterprises rely on Maltrail to enhance their cybersecurity posture. The software provides valuable insights for IT teams to mitigate risks and prevent intrusions. It is widely used for its easy setup and comprehensive monitoring capabilities. The primary purpose of Maltrail is to maintain network integrity by detecting and reporting possible security incidents.

Remote Code Execution (RCE) is a critical vulnerability that allows an attacker to execute arbitrary commands on a target system. This vulnerability in Maltrail's username parameter at the /login endpoint can be exploited by remote attackers. The impact of this includes potential system compromise and unauthorized control of the affected server. Attackers leveraging this vulnerability gain the ability to manipulate system operations remotely with malicious intent. Organizations with vulnerable versions may face severe security risks, necessitating immediate attention to patch or mitigate this flaw. The scope of the vulnerability underscores the need for robust security measures in monitoring systems.

The vulnerability is located in the /login endpoint of Maltrail, where the username parameter accepts user input. This parameter is poorly sanitized, allowing attackers to inject and execute commands on the server. The lack of adequate input validation opens up the potential for remote manipulation of the server environment. Attackers can send specially crafted POST requests containing malicious payloads to exploit this flaw. The vulnerability showcases the importance of secure coding practices, particularly in authentication processes. Proper patching and input validation are critical to safeguarding against such vulnerabilities.

Exploitation of this vulnerability can lead to unauthorized access and control of the affected system. Malicious actors might use this to deploy additional malware, steal sensitive information, or disrupt services. In severe cases, it could result in full system compromise, posing significant threats to business operations and data integrity. The consequences of exploitation are detrimental to organizational security, potentially resulting in financial losses and reputational harm. It highlights the necessity for regular security assessments and updates to protect against evolving threats. Organizations must deploy appropriate measures to counteract such vulnerabilities effectively.

REFERENCES

Solution Advice
  • Update Maltrail to the latest version to apply necessary security patches.
  • Implement stringent input validation to prevent unauthorized command execution.
  • Regularly monitor and audit systems for unusual activity indicative of exploitation.
  • Restrict access to critical endpoints and employ robust authentication mechanisms.
  • Consider employing additional security controls such as Web Application Firewalls (WAFs) to detect and block exploitation attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2025-34073 Scanner - Remote Code Execution vulnerability in Maltrail S4E