CVE-2025-53880: Suse Container suse/manager/4.3/proxy-Httpd:latest

High severity, CVSS 8.7. EPSS: 0.3% chance of exploitation in the next 30 days.

A Path Traversal vulnerability in the tftpsync/add and tftpsync/delete scripts allows a remote attacker on an adjacent network to write or delete files on the filesystem with the privileges of the unprivileged wwwrun user. Although the endpoint is unauthenticated, access is restricted to a list of allowed IP addresses.

Affected products

  • Suse Container suse/manager/4.3/proxy-Httpd:latest
  • Suse Container suse/manager/5.0/x86 64/proxy-Httpd:latest
  • Suse Container Suse/multi-Linux-manager/5.1/x86 64/proxy-Httpd:latest
  • Suse Suse Manager Proxy LTS 4.3

Published 2025-10-30. Last modified 2026-06-17.