CVE-2025-5880 is a path traversal vulnerability in Whistle 2.9.98. The issue affects unknown code in the /cgi-bin/sessions/get-temp-file endpoint, where the filename argument is not properly restricted or sanitized. By manipulating this parameter, an attacker can cause the application to access files outside the intended directory scope. Public disclosure indicates that exploit details are available. Based on the provided information, the flaw is limited to path traversal via the filename parameter; no further implementation details about the vulnerable function are currently available.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small standalone proof-of-concept for CVE-2025-5880 affecting Whistle <= 2.9.98. It contains two files: a README describing the vulnerability, usage, and examples, and a single Python exploit script (poc.py). The script is the main entry point and uses only Python standard library modules (argparse, urllib, json, sys, datetime; os imported in sweep mode), so there are no external dependencies. The exploit capability is unauthenticated arbitrary file read over the network. It targets the Whistle endpoint /cgi-bin/sessions/get-temp-file and appends an attacker-controlled filename query parameter directly to the request URL. The script assumes the server returns a JSON object containing a value field with file contents, but it also falls back to raw response decoding if JSON parsing fails. Retrieved content is printed to the console and can optionally be written to local files. Operationally, the script supports three modes: reading a single arbitrary file via --file, reading one predefined sensitive target via --preset, and sweeping all predefined targets via --sweep. Presets include common Linux-sensitive paths such as /etc/passwd, /etc/shadow, /etc/hosts, root SSH keys, and /proc/self metadata. In sweep mode it can create a local directory and save each successful result as a separate text file. Overall, this is a real exploit rather than a detector: it actively sends exploitation requests and extracts file contents from the target. It is best classified as OPERATIONAL because it includes working exploitation logic and basic exfiltration/output handling, but it is not part of a larger exploitation framework and does not provide advanced payload customization beyond selecting file paths.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.