CRITICAL🇵🇱 Wersja polska

CVE-2025-29331

CVSS 9.8v3.1pub. 2025-06-26upd. 2025-07-10

An issue in MHSanaei 3x-ui before v.2.5.3 and before allows a remote attacker to execute arbitrary code via the management script x-ui passes the no check certificate option to wget when downloading updates

🤖 AI Analysis
How it works

The x-ui management script calls the wget tool with an option that disables TLS certificate verification (--no-check-certificate) during update download. This means the HTTPS connection is not properly validated, and an attacker on the network path can substitute a malicious payload for the legitimate update. The downloaded and executed file can contain arbitrary code that will run in the context of the management script's privileges.

Impact

An attacker can execute arbitrary code on the victim's server, which in practice means complete takeover of the system, including access to configuration data, keys, and network traffic handled by 3X-Ui.

Mitigation & patch

Update 3X-Ui to version 2.5.3 or newer. Patch details are available in the vendor references (pull request #2661 on GitHub).

Who is affected

MHSanaei 3X-Ui in versions before v2.5.3

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Mhsanaei 3x Ui

    APP
    Mhsanaei
    < 2.5.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References