CVE-2025-54322: Code Injection
Published Dec 27, 2025
·Updated
Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used.
Affected Software
2 affected components
Xspeeder Sxzos<=2025-12-26
Xspeeder Sxzos<=2025-12-26
Event History
Dec 27, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Jan 4, 2026
News Published
via The Register·07:02 PM
News Published
via The Register·07:06 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-54322?
CVE-2025-54322 has been classified as critical due to its potential for remote code execution by unauthenticated users.
2
How do I fix CVE-2025-54322?
To fix CVE-2025-54322, upgrade to a version of Xspeeder SXZOS released after December 26, 2025, which addresses this vulnerability.
3
What impact does CVE-2025-54322 have on my system?
CVE-2025-54322 allows an attacker to execute arbitrary code with root privileges, potentially compromising the entire system.
4
What are the affected versions for CVE-2025-54322?
CVE-2025-54322 affects Xspeeder SXZOS versions up to and including 2025-12-26.
5
Is there a workaround for CVE-2025-54322?
As of now, there are no known effective workarounds for CVE-2025-54322; upgrading to a secure version is recommended.