---
cve: "CVE-2025-67738"
severity: "HIGH"
cvss: 8.5
epss: "0.4%"
vendor: "Webmin"
kev: false
exploited: false
published: "2025-12-11 07:16:00"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-10-03T21:51:28+02:00"
---

# CVE-2025-67738

> 8.5 HIGH · 🧪 PoC

## Beschreibung

squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module and its Cache Manager feature are available, and an untrusted party is able to authenticate to Webmin and has certain Cache Manager permissions (the "cms" security option).

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **no**
  - Technical Impact: **total**

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Hoch | good |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- 3d300b5fb60b30ab768ac57034a84b93613e9a94 (Commit)
- 1a52bf4d72f9da6d79250c66e51f41c6f5b880ee (Commit)

## BSI-Hinweise (deutsch)

- [Webmin: Schwachstelle ermöglicht Codeausführung](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2025-2813) — _BSI-Einstufung: hoch_
  Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Webmin ausnutzen, um beliebigen Programmcode auszuführen.

## Referenzen

- <https://github.com/webmin/webmin/commit/1a52bf4d72f9da6d79250c66e51f41c6f5b880ee>
- <https://github.com/webmin/webmin/compare/2.520...2.600>
- <https://webmin.com/security/#privilige-escalation-using-squid-module-cve-2025-67738>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-67738) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
