CVE-2025-29331 Information

Description

An issue in MHSanaei 3x-ui before v.2.5.3 and before allows a remote attacker to execute arbitrary code via the management script x-ui passes the no check certificate option to wget when downloading updates

Reference

https://github.com/MHSanaei/3x-ui/pull/2661 https://www.digilol.net/security-advisories/dlsec2025-001.html

CNNVD-202506-3314 (Published: 2025-06-26)

Share on: