Critical Convoy Flaw Allows Remote Code Execution on Servers

Critical Convoy Flaw Allows Remote Code Execution on Servers

A critical vulnerability (CVE-2025-52562) affects the Performave Convoy KVM server management panel, allowing remote attackers to execute arbitrary code without authentication. This flaw could lead to full server compromise, data theft, and malicious payload execution. #ConvoyVulnerability #CVE202552562

Keypoints

  • The vulnerability exists in Convoy’s LocaleController component due to improper input validation.
  • Attackers can perform directory traversal and include malicious PHP files remotely.
  • Exploitation enables remote code execution with SYSTEM-level privileges.
  • Unauthenticated attackers can access sensitive data such as database credentials and API keys.
  • Immediate patching to version 4.4.1 or later is crucial to prevent attacks.

Read More: https://gbhackers.com/critical-convoy-flaw/