CVE-2025-55125
Unknown
Unknown - Not Provided
Remote Code Execution via Malicious Backup Config in Tape Software
Publication date: 2026-01-08
Last updated on: 2026-01-08
Assigner: HackerOne
Description
Description
This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious
backup configuration file.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| veeam | backup_and_replication | to 13.0.1.1071 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |