CVE-2025-54322: Xspeeder Sxzos
Critical severity, CVSS 9.8. EPSS: 15.1% chance of exploitation in the next 30 days.
Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used.
Affected products
- Xspeeder Sxzos: up to and including 2025-12-26
Published 2025-12-27. Last modified 2026-10-07.