---
id: CVE-2025-54322
title: >-
  Xspeeder SXZOS through 2025-12-26 allows root remote code execution via
  base64-encoded Python code in the chkid parameter to vLogin.py
summary: >-
  Xspeeder SXZOS through 2025-12-26 allows root remote code execution via
  base64-encoded Python code in the chkid parameter to vLogin.py. The title and
  oIP parameters are also used.
severity: critical
cvss: 10
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-95
  - CWE-94
vendor: xspeeder
product: sxzos
affected:
  - sxzos <= 2025-12-26
published: '2025-12-27'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T19:10:00.210'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-54322'
references:
  - url: >-
      https://pwn.ai/blog/cve-2025-54322-zeroday-unauthenticated-root-rce-affecting-70-000-hosts
    label: cve@mitre.org
  - url: 'https://www.xspeeder.com'
    label: cve@mitre.org
  - url: >-
      https://pwn.ai/blog/cve-2025-54322-zeroday-unauthenticated-root-rce-affecting-70-000-hosts
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - exploit-available
epss: 0.15146
epssPercentile: 0.96652
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/Sachinart/CVE-2025-54322'
    - 'https://github.com/nkuty/CVE-2025-54322-exploit'
  checkedAt: '2026-10-05T19:31:35.328Z'
exploitAvailable: true
ingestedAt: '2026-10-05T19:30:59.941Z'
---

## Overview

Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used.

## Affected

- `sxzos <= 2025-12-26`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
