boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2025-27920

Srimax Output Messenger
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0186   78.6   YES
AFFECTED
  Product           Versions     Fixed
  Output Messenger  unspecified  —
TIMELINE
  Mar 10  Reserved by mitre
  May 5   Published (CNA: mitre)
  May 19  Added to CISA KEV, remediation due 2025-06-09
CWE-24 · CNA: mitre · CVSS v3.1 · 4 references · KEV due June 9, 2025

Description

Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
March 10, 2025ReservedReserved by mitre
May 5, 2025PublishedPublished (CNA: mitre)
May 19, 2025KEV ADDEDAdded to CISA KEV, remediation due 2025-06-09

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
SrimaxOutput Messenger———

Weaknesses

CWE-24

References (4)

Related

Authoritative record: CVE-2025-27920 at cve.org

Vendors: srimax

Weaknesses: CWE-24

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-27920 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.