S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated May 13, 2026

CVE-2025-34030 Scanner

CVE-2025-34030 Scanner - Remote Code Execution (RCE) vulnerability in sar2html

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.6k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-34030
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

An OS command injection vulnerability exists in sar2html version 3.2.2 and prior via the plot parameter in index.php. The application fails to sanitize user-supplied input before using it in a system-level context. Remote, unauthenticated attackers can inject shell commands by appending them to the plot parameter (e.g., ?plot=;id) in a crafted GET request. The output of the command is displayed in the application's interface after interacting with the host selection UI. Successful exploitation leads to arbitrary command execution on the underlying system. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-04 UTC.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
sar2htmlby sar2html
0
Updated Aug 22, 2026View on NVD →
Detail

The sar2html application is a popular tool used for graphically viewing and analyzing system activity reports (SAR) data. It is commonly used among system administrators and IT professionals for monitoring system performance and troubleshooting. Sar2html is designed to convert SAR data into an easy-to-read HTML format. Organizations rely on sar2html for comprehensive system performance analysis, making it a crucial tool in server management and optimization tasks. The software is often deployed on web servers, allowing remote access to system performance metrics.

The vulnerability detected is a Remote Code Execution (RCE) weakness in the sar2html product. This allows attackers to insert and execute harmful code via the plot parameter of the index.php file. The issue arises due to insufficient input validation of the plot parameter, leaving the system open to OS command injection. This vulnerability can be exploited by unauthenticated attackers over the network, posing a severe threat to any system running the affected version of sar2html.

Technical details reveal that the vulnerability resides in the lack of sanitation within the plot parameter of the index.php script. By appending shell metacharacters to this parameter, attackers can insert and execute arbitrary code on the server. The HTTP request containing the exploit is crafted to inject OS commands directly, which are executed in the web application process context. This lack of proper input validation and handling makes the vulnerability critical and relatively easy to exploit.

If exploited by malicious actors, this vulnerability can lead to unauthorized remote command execution on the server hosting sar2html. The attacker can gain control over the server, potentially leading to data theft, service disruptions, or the deployment of further malicious software. Additionally, this could compromise the confidentiality, integrity, and availability of data and services hosted on the affected system.

REFERENCES

Solution Advice
  • Remove public access to vulnerable sar2html installations to reduce exposure.
  • Apply vendor-released patches immediately to remediate the vulnerability.
  • Configure access controls to restrict sar2html application access to trusted users only.
  • Implement intrusion detection systems to monitor attempts at exploiting similar vulnerabilities.
  • Consider disabling unused functions or replacing sar2html with alternative tools if patching is delayed.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.