CVE-2025-34121: Idera Up.Time ≤ 7.2 post2file.php Arbitrary File Upload RCE
An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station versions up to and including 7.2. The wizards/post2file.php script accepts arbitrary POST parameters, allowing attackers to upload crafted PHP files to the webroot. Successful exploitation results in remote code execution as the web server user. NOTE: The bypass for this vulnerability is tracked as CVE-2015-9263.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34121?
CVE-2025-34121 has a high severity rating due to its potential for unauthorized remote code execution.
How do I fix CVE-2025-34121?
To fix CVE-2025-34121, upgrade Idera Up.Time Monitoring Station to version 7.3 or later.
What versions of Idera Up.Time Monitoring Station are affected by CVE-2025-34121?
CVE-2025-34121 affects all versions of Idera Up.Time Monitoring Station up to and including 7.2.
Can CVE-2025-34121 be exploited remotely?
Yes, CVE-2025-34121 can be exploited remotely by an attacker due to its unauthenticated file upload nature.
What type of vulnerability is CVE-2025-34121?
CVE-2025-34121 is classified as an arbitrary file upload vulnerability.