CVE-2025-34121 is an unauthenticated arbitrary file upload vulnerability affecting Idera Up.Time Monitoring Station versions up to and including 7.2. The issue is in the wizards/post2file.php script, which accepts arbitrary POST parameters and can be abused to upload attacker-controlled files into the webroot. By uploading a crafted PHP file, a remote attacker can cause the application to place executable server-side code in a web-accessible location and then invoke it, resulting in remote code execution. The provided context notes that a bypass related to this vulnerability is tracked separately as CVE-2015-9263.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
wizards/post2file.php endpoint. Disable execution of PHP or other server-side scripts in upload-accessible directories, move writable directories outside the webroot, and apply web server rules to deny requests to newly uploaded executable content. Use network ACLs, reverse proxy filtering, or WAF rules to limit access to the vulnerable path and monitor for suspicious POST requests and unexpected files written under the webroot. Conduct a compromise assessment for unauthorized PHP files or web shells on affected systems.Patch, then assume compromise.
wizards/post2file.php functionality should be removed, disabled, or modified so it does not accept arbitrary POST parameters for file creation in web-accessible directories. Server-side validation should strictly restrict uploaded content, enforce allowlisted file types, prevent upload of executable server-side scripts such as PHP, and store uploaded files outside the webroot. Review the vendor's guidance for any patch or hotfix addressing CVE-2025-34121 and the related bypass tracked as CVE-2015-9263.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (modules/exploits/multi/http/uptime_file_upload_1.rb) targeting an arbitrary file upload vulnerability in Idera Up.Time Monitoring Station versions 7.2 and below. The exploit abuses the 'wizards/post2file.php' endpoint to upload a PHP payload to the webroot without authentication, then executes the payload to achieve remote code execution. The module is fully weaponized, allowing the attacker to specify any Metasploit PHP payload. The code is written in Ruby and leverages Metasploit's HttpClient and PhpEXE mixins. The main endpoints involved are '/wizards/post2file.php' for the upload and '/wizards/<random>.php' for payload execution. The exploit is associated with CVE-2025-34121 and is suitable for operational use against vulnerable Up.Time installations.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.