CVE-2025-27234: Zabbix
High severity, CVSS 7.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. In Zabbix 5.0 this allows for remote code execution.
Affected products
- Zabbix Zabbix
Published 2025-09-12. Last modified 2026-06-17.