CVE-2025-34098 is a path traversal vulnerability in Riverbed SteelHead VCX appliances, confirmed in VCX255U version 9.6.0a. The flaw is caused by improper input validation in the log filtering functionality exposed through the management web interface. Specifically, an authenticated attacker can submit crafted filter expressions to the log_filter endpoint via the filterStr parameter. The backend parser processes this input in a way that permits file expansion syntax, which can be abused to traverse paths and cause arbitrary system files to be retrieved through the log viewing interface.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit auxiliary module that exploits an authenticated arbitrary file read vulnerability (CVE-2025-34098) in the Riverbed SteelHead VCX (VCX255U) version 9.6.0a. The module requires valid credentials to authenticate to the device's web interface. It first retrieves a CSRF token, then authenticates using the provided username and password, and finally abuses the log module's filter engine to read arbitrary files from the system (defaulting to /etc/shadow). The file contents are parsed from the JSON response and stored as loot in Metasploit. The module is written in Ruby and leverages Metasploit's HTTP client and scanner mixins. The main endpoints involved are /login for authentication and /modules/common/logs for the file read operation. The exploit is operational and provides a practical method for attackers with credentials to extract sensitive files from vulnerable devices.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.