← Vulnerability feed

Vulnerability record · CVE-2025-64348 · published 31 October 2025

CVE-2025-64348: Elog project elog missing authorization vulnerability

Elog Project · Elog

ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the execute facility is specifically enabled with the "-x" command line flag, attackers could execute OS commands on the host machine. By default, ELOG is not configured to allow shell commands or self-registration.

7.1 CVSS 4.0 High EPSS 0.30% · top 79.7% CWE-862 · Missing authorization
7.1CVSS 4.0 base score
0.30%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the execute facility is specifically enabled with the "-x" command line flag, attackers could execute OS commands on the host machine. By default, ELOG is not configured to allow shell commands or self-registration.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-64348 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2025-64349Elog project elog missing authorization vulnerabilityELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address, then request a password reset…EPSS 0.35%8.6CVE-2025-62618Elog project elog cross-site scripting vulnerabilityELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other users when they open the file.…EPSS 0.30%7.5CVE-2019-3992Elog project elog information exposure vulnerabilityELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can access the server's config…EPSS 1.3%7.5CVE-2019-3993ELOG unauthenticated password hash disclosure via crafted HTTP POSTELOG 3.1.4-57bea22 and below exposes user password hashes to a remote attacker who sends a crafted HTTP POST request. No authentication or user inter…EPSS 46%analysed7.5CVE-2019-3994Elog project elog use after free vulnerabilityELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a use after free. A remote unauthenticated attacker can crash th…EPSS 2.9%7.5CVE-2019-3995Elog project elog null pointer dereference vulnerabilityELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a NULL pointer dereference. A remote unauthenticated attacker ca…EPSS 29%7.5CVE-2016-6342Fedoraproject fedora improper access control vulnerabilityelog 3.1.1 allows remote attackers to post data as any username in the logbook.EPSS 1.0%6.5CVE-2019-3996Elog project elog vulnerabilityELOG 3.1.4-57bea22 and below can be used as an HTTP GET request proxy when unauthenticated remote attackers send crafted HTTP POST requests.EPSS 5.9%

Source: NIST National Vulnerability Database (record CVE-2025-64348), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.