CVE-2025-62878 - Vulnerability Analysis
CriticalCVSS: 9.9Last Updated: February 25, 2026
Unknown Product - Path Traversal
Overview
A product contains a path traversal caused by manipulation of parameters.pathPattern, letting attackers create PersistentVolumes in arbitrary host locations, potentially overwriting sensitive files or accessing unintended directories, exploit requires no special privileges.
Severity & Score
Impact
Attackers can overwrite sensitive files or access unintended directories on the host, risking data integrity and confidentiality.
Mitigation
Update to the latest version or apply vendor patches addressing path traversal in PersistentVolumes.
References
Social Media Activity(1 post)
š“ CVE-2025-62878 - Critical (9.9) A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the host node, potentially overwriting sensitive files or gaining access to unintended directories. š https://www.thehackerwire.com/vulnerability/CVE-2025-62878/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postGitHub Repositories(1 repo)
Related Resources
Details
- CVE ID
- CVE-2025-62878
- Severity
- Critical
- CVSS Score
- 9.9
- Type
- path_traversal
- Status
- unconfirmed
- EPSS
- 2.4%
- Social Posts
- 1
CWE
- CWE-23
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H