CVE advisoryCRITICAL
CVE-2025-54322
Xspeeder SXZOS Root Code Execution Vulnerability
Halo Surface Signal: 5 out of 5 — more likely to be public-facing.
A critical vulnerability exists in Xspeeder SXZOS, allowing unauthenticated root remote code execution via base64-encoded Python code in the `chkid` parameter of vLogin.py. This could lead to a complete system compromise, making it crucial to identify and assess affected systems.