CVE-2019-25352: Genivia Inc Crystal Live HTTP Server

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

Crystal Live HTTP Server 6.01 contains a directory traversal vulnerability that allows remote attackers to access system files by manipulating URL path segments. Attackers can use multiple '../' sequences to navigate outside the web root and retrieve sensitive configuration files like Windows system files.

Affected products

  • Genivia Inc Crystal Live HTTP Server: version 6.01 only

Published 2026-02-18. Last modified 2026-06-17.