CVE-2025-47423: Pwsdashboard Personal Weather Station Dashboard

Medium severity, CVSS 5.8. EPSS: 2% chance of exploitation in the next 30 days.

Personal Weather Station Dashboard 12_lts allows unauthenticated remote attackers to read arbitrary files via ../ directory traversal in the test parameter to /others/_test.php, as demonstrated by reading the server's private SSL key in cleartext.

Affected products

  • Pwsdashboard Personal Weather Station Dashboard: version 12_lts only

Published 2025-05-07. Last modified 2026-06-17.