CVE-2025-63261: Command Injection
Published Mar 20, 2026
·Updated
AWStats 8.0 is vulnerable to Command Injection via the open function
Affected Software
3 affected components
Awstats AWStats=8.0
Awstats AWStats=7.9
Debian Debian Linux=11.0
Event History
Mar 20, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-63261?
CVE-2025-63261 is classified as a critical vulnerability due to its potential for command injection.
2
How do I fix CVE-2025-63261?
To fix CVE-2025-63261, upgrade AWStats to version 8.1 or later, as it addresses the vulnerability.
3
What impact does CVE-2025-63261 have on system security?
CVE-2025-63261 allows attackers to execute arbitrary commands, compromising the security and integrity of the server.
4
Is CVE-2025-63261 a remote or local vulnerability?
CVE-2025-63261 is a remote vulnerability that attackers can exploit over the network.
5
Who is affected by CVE-2025-63261?
CVE-2025-63261 affects users of AWStats version 8.0.