← Browse

CVE-2025-27920

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
EPSS — probability of exploitation (30 days)
1.9%
78.2th percentile
CISA KEV
Listed
Added 2025-05-19 · patch by 2025-06-09
Weakness / dates
Published — · modified —

Timeline

Description

Srimax Output Messenger contains a directory traversal vulnerability that allows an attacker to access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.

Official: NVD · CVE.org