CVE-2025-47423: Pwsdashboard Personal Weather Station Dashboard
Medium severity, CVSS 5.8. EPSS: 2% chance of exploitation in the next 30 days.
Personal Weather Station Dashboard 12_lts allows unauthenticated remote attackers to read arbitrary files via ../ directory traversal in the test parameter to /others/_test.php, as demonstrated by reading the server's private SSL key in cleartext.
Affected products
- Pwsdashboard Personal Weather Station Dashboard: version 12_lts only
Published 2025-05-07. Last modified 2026-06-17.