Intelligence View
⚡ tsecurity.de Intelligence
CVE-2025-54314 | Rails Thor up to 1.3.x Shell Command os command injection (Nessus ID 243473)
A vulnerability was found in Rails Thor up to 1.3.x. It has been declared as critical. This vulnerability affects unknown code of the component Shell Command…
A vulnerability was found in Rails Thor up to 1.3.x. It has been declared as critical. This vulnerability affects unknown code of the component Shell Command Handler. The manipulation leads to os command injection.
This vulnerability was named CVE-2025-54314. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
This vulnerability was named CVE-2025-54314. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege
Compliance, SLA & Vendor Adherence
Advisory-Prüfung · Score-Einordnung · Fristen
CVSS 2.8CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
Impact: 1.44 | Exploitability: 1.15
AVL
Lokal (Dateisystem / SSH)
Erfordert bereits ein lokales Benutzerkonto oder Ausführung vor Ort.
ACH
Hoch (High)
Erfordert Vorwissen, spezifische Zeitfenster oder unzuverlässige Race Conditions.
PRL
Niedrig (Standard-Benutzer)
Erfordert Anmeldedaten eines regulären Benutzers.
UIN
Keine (Zero-Click)
Autonom ohne menschliches Zutun ausführbar (Zero-Click Exploitation).
SC
Verändert (Scope Changed)
Kann auf übergeordnete Systeme oder Hypervisor/Cloud-Ebene übergreifen (Sandbox Escape).
CN
Keine
Teilweiser oder kein Datenabfluss.
IL
Gering (Teilweise)
Teilweise oder keine Manipulation.
AN
Keine
Teilweise oder keine Beeinträchtigung.
BSI-Warnung (Deutschland)CVE-2025-54314
Xerox FreeFlow Print Server: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff28.05.2026CISA-SSVC-Triage (vulnrichment)CVE-2025-54314
Exploitation: none (Keine bekannte Ausnutzung)Automatable: no (Nicht automatisierbar)Technical Impact: partial (Teilweise)
Quelle: CISA-ADP vulnrichment · Stand 2025-07-21T18:31:26.798255Z · CISA Coordinator
Advisory Radar
In herstellerseitiger Prüfung
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Hersteller-Advisory noch nicht formal hinterlegt. Regelmäßiges Re-Scanning der CTI-Quellen anberaumt.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com
-
Web Referencehackerone.com
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com