Skip to main content
HIGH

CVE-2019-25355

Genivia gSOAP 2.8 - 'gSOAP' Path Traversal

CVSS v3

7.5

HIGH

EPSS Score

1.3 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

poc

SSVC status

Description

gSOAP 2.8 contains a directory traversal vulnerability that allows unauthenticated attackers to access system files by manipulating HTTP path traversal techniques. Attackers can retrieve sensitive files like /etc/passwd by sending crafted GET requests with multiple '../' directory traversal sequences.

Technical details

Published
2026-02-18
Last Modified
2026-02-26

Frequently asked questions

What is CVE-2019-25355?

gSOAP 2.8 contains a directory traversal vulnerability that allows unauthenticated attackers to access system files by manipulating HTTP path traversal techniques. Attackers can retrieve sensitive files like /etc/passwd by sending crafted GET requests with multiple '../' directory traversal sequences.

Is CVE-2019-25355 actively exploited?

A proof-of-concept exploit exists for CVE-2019-25355, but active exploitation has not been confirmed at this time.

What is the CVSS score for CVE-2019-25355?

CVE-2019-25355 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2019-25355 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key