Critical unauthenticated remote code execution vulnerability in Commvault Command Center that allows attackers to upload malicious ZIP packages containing JSP files via path traversal. The vulnerability enables complete server compromise without authentication and is actively being exploited in the wild.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2025-04-22
Added to CISA KEV: 2025-05-02 10 DAYS BETWEEN CVE AND KEV
CVE-2025-34028 is a critical security vulnerability affecting Commvault Command Center, which has been confirmed as being actively exploited in the wild [1].
Commvault Command Center contains a path traversal vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code.
This script is a proof of concept for CVE-2025-34028, for Commvault Web Interfaces. By uploading a zip file containing a code execution .jsp file,โฆ
Description. The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, ...
A path traversal vulnerability in Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files, which, when expanded by the target server, result in Remote Code Execution. This issue affects Command Center Innovation Release: 11.38. Unauthenticated attackers can ..
CVE-2025-34028 is a critical remote code execution vulnerability in Commvault Command Center, rated with a CVSS score of 10.0.