S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Oct 12, 2025

CVE-2025-61666 Scanner

CVE-2025-61666 Scanner - Local File Inclusion (LFI) vulnerability in Traccar (Windows)

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-61666
8.7
CVSShigh
Exploitable remotely over the internet · no authentication required.

Traccar is an open source GPS tracking system. Default installs of Traccar on Windows between versions 6.1- 6.8.1 and non default installs between versions 5.8 - 6.0 are vulnerable to unauthenticated local file inclusion attacks which can lead to leakage of passwords or any file on the file system including the Traccar configuration file. Versions 5.8 - 6.0 are only vulnerable if <entry key='web.override'>./override</entry> is set in the configuration file. Versions 6.1 - 6.8.1 are vulnerable by default as the web override is enabled by default. The vulnerable code is removed in version 6.9.0.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
traccarby traccar
>= 5.8, < 6.9.0
Updated Aug 19, 2026View on NVD →
Detail

Traccar is an open-source GPS tracking system commonly used by organizations and individuals to track vehicle movements and monitor fleet operations. It operates on multiple platforms including Windows, and offers a variety of functionalities such as real-time tracking, geofencing, and alerts. Traccar's ease of use and powerful feature set are beneficial for transportation companies and logistics providers. The application can be integrated with various GPS tracking devices to provide comprehensive location data. Users can manage their fleet and optimize routes through the Traccar web interface. The software allows for detailed reporting and analysis, which is crucial for efficient fleet management.

This vulnerability, known as Local File Inclusion (LFI), allows attackers to read sensitive files from the server. The LFI vulnerability in Traccar (Windows) versions 6.1-6.8.1 enables unauthenticated attackers to access arbitrary files due to improper input handling. The attack exploits directory traversal sequences to navigate the file system and includes local files. By exploiting this vulnerability, malicious actors can obtain sensitive information such as database configurations and other confidential data. The vulnerability primarily affects Traccar installations with specific configurations.

The Local File Inclusion vulnerability in Traccar (Windows) involves improper input validation in web requests. Attackers can craft URLs with directory traversal patterns to access sensitive files on the server. The vulnerability is typically exploited by inserting special character sequences like "..%5c" in HTTP requests. Successful exploitation allows attackers to include and read arbitrary files, potentially exposing critical configuration files. This weakness can be leveraged to steal database credentials and other sensitive information stored in the configuration files. The vulnerability is particularly concerning because it can be exploited remotely without requiring authentication.

Exploitation of this vulnerability can result in significant data breaches, potentially exposing sensitive information like database passwords. If leveraged by malicious actors, it could lead to unauthorized access to the system and further exploitation of sensitive data. Additionally, this vulnerability could compromise the integrity of the application by allowing unauthorized file inclusion. Organizations using vulnerable versions may experience a loss of data confidentiality and possible operational disruptions. The unauthorized disclosure of files can lead to privacy infringements and have financial implications due to data exposure.

REFERENCES

Solution Advice
  • Upgrade to Traccar version 6.9.0 or later to mitigate this vulnerability.
  • Ensure that input validation mechanisms are in place to prevent directory traversal sequences.
  • Regularly review and monitor server access logs to detect unauthorized file access attempts.
  • Implement safeguards such as web application firewalls to filter out malicious requests.
  • Regularly audit system configurations to ensure deployed software versions are secure.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.