{"id":"CVE-2025-54322","title":"Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py","summary":"Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used.","severity":"critical","cvss":10,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-95","CWE-94"],"vendor":"xspeeder","product":"sxzos","affected":["sxzos <= 2025-12-26"],"published":"2025-12-27","updated":"2026-10-05","sourceUpdated":"2026-10-05T19:10:00.210","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-54322","references":[{"url":"https://pwn.ai/blog/cve-2025-54322-zeroday-unauthenticated-root-rce-affecting-70-000-hosts","label":"cve@mitre.org"},{"url":"https://www.xspeeder.com","label":"cve@mitre.org"},{"url":"https://pwn.ai/blog/cve-2025-54322-zeroday-unauthenticated-root-rce-affecting-70-000-hosts","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","exploit-available"],"epss":0.15146,"epssPercentile":0.96652,"exploits":{"github":2,"githubRepos":["https://github.com/Sachinart/CVE-2025-54322","https://github.com/nkuty/CVE-2025-54322-exploit"],"checkedAt":"2026-10-05T19:31:35.328Z"},"exploitAvailable":true,"ingestedAt":"2026-10-05T19:30:59.941Z","slug":"CVE-2025-54322","body":"## Overview\n\nXspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used.\n\n## Affected\n\n- `sxzos <= 2025-12-26`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":70,"depthScoreParts":{"impact":55,"likelihood":3,"exploitation":12,"ransomware":0},"changes":[]}