CVE-2025-67728Critical· 9.8▾ MidnightFireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and below allow an authenticated user, or unauthenticated user if the Public Uploads setting is enabled, to craft a malicious filename when uploading a video file.…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.7%
Fireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and below allow an authenticated user, or unauthenticated user if the Public Uploads setting is enabled, to craft a malicious filename when uploading a video file. The malicious filename is then concatenated directly into a shell command, which can be used for uploading files to arbitrary directories via path traversal, or executing system commands for Remote Code Execution (RCE). This issue is fixed in version 1.3.0.
fireshare < 1.3.0Upgrade past the affected range:
fireshare 1.3.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54544High· 7.2Fireshare facilitates self-hosted media and link sharing
CVE-2026-54337Critical· 9.8Fireshare facilitates self-hosted media and link sharing
CVE-2025-14225Medium· 6.3A vulnerability was determined in D-Link DCS-930L 1.15.04
CVE-2025-14707Critical· 9.8A security flaw has been discovered in Shiguangwu sgwbox N3 2.0.25
CVE-2025-14706Critical· 9.8A vulnerability was identified in Shiguangwu sgwbox N3 2.0.25
CVE-2025-14705Critical· 9.8A vulnerability was determined in Shiguangwu sgwbox N3 2.0.25