CVE-2025-61666

Traccar is an open source GPS tracking system. Default installs of Traccar on Windows between versions 6.1- 6.8.1 and non default installs between versions 5.8 - 6.0 are vulnerable to unauthenticated local file inclusion attacks which can lead to leakage of passwords or any file on the file system including the Traccar configuration file. Versions 5.8 - 6.0 are only vulnerable if <entry key='web.override'>./override</entry> is set in the configuration file. Versions 6.1 - 6.8.1 are vulnerable by default as the web override is enabled by default. The vulnerable code is removed in version 6.9.0.
CVSS

No CVSS.

Configurations

No configuration.

History

03 Oct 2025, 16:16

Type Values Removed Values Added
References
  • () https://projectblack.io/blog/jetty-addpath-lfiĀ -

02 Oct 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-02 22:15

Updated : 2025-10-06 14:57


NVD link : CVE-2025-61666

Mitre link : CVE-2025-61666

CVE.ORG link : CVE-2025-61666


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')