LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2025-60946

CVE-2025-60946 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: March 23, 2026

Census CSWeb - Path Traversal

Published: March 23, 2026Updated: March 23, 2026Remote Exploitable

Overview

Census CSWeb 8.0.1 contains a path traversal caused by arbitrary file path input, letting remote authenticated attackers access unintended file directories, exploit requires authentication.

Severity & Score

Severity: High
CVSS Score: 8.8
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Remote authenticated attackers can access unintended file directories, potentially exposing sensitive information.

Mitigation

Update to version 8.1.0 alpha or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 23, 2026

🟠 CVE-2025-60946 - High (8.8) Census CSWeb 8.0.1 allows arbitrary file path input. A remote, authenticated attacker could access unintended file directories. Fixed in 8.1.0 alpha. šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2025-60946/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 23, 2026

🟠 CVE-2025-60946 - High (8.8) Census CSWeb 8.0.1 allows arbitrary file path input. A remote, authenticated attacker could access unintended file directories. Fixed in 8.1.0 alpha. šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2025-60946/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2025-60946
Severity
High
CVSS Score
8.8
Type
path_traversal
Status
new
EPSS
0.0%
Social Posts
2

CWE

  • CWE-22

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score

0.0%Probability of exploitation in the next 30 days