CVE-2025-54322: Xspeeder Sxzos

Critical severity, CVSS 9.8. EPSS: 15.1% chance of exploitation in the next 30 days.

Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used.

Affected products

  • Xspeeder Sxzos: up to and including 2025-12-26

Published 2025-12-27. Last modified 2026-10-07.