CVE-2025-55125
Unknown Unknown - Not Provided
Remote Code Execution via Malicious Backup Config in Tape Software

Publication date: 2026-01-08

Last updated on: 2026-01-08

Assigner: HackerOne

Description
This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-01-08
Last Modified
2026-01-08
Generated
2026-06-16
AI Q&A
2026-01-08
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
veeam backup_and_replication to 13.0.1.1071 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability in Veeam Backup & Replication allows a Backup or Tape Operator to execute remote code as the root user by creating a malicious backup configuration file. This means an attacker with Backup or Tape Operator privileges can gain full control over the system remotely by exploiting this flaw. [1]

Impact Analysis

The vulnerability can lead to remote code execution with root privileges, allowing an attacker to fully compromise the affected system. This can result in unauthorized access, data theft, data corruption, or disruption of backup services, severely impacting system confidentiality, integrity, and availability. [1]

Mitigation Strategies

Users are strongly advised to update Veeam Backup & Replication to version 13.0.1.1071 or later, as this version resolves the vulnerability allowing remote code execution by a Backup or Tape Operator via a malicious backup configuration file. [1]

Compliance Impact

The vulnerability allows remote code execution with root privileges, which can lead to unauthorized access, modification, or destruction of sensitive data. This poses a significant risk to the confidentiality, integrity, and availability of data, potentially resulting in non-compliance with data protection standards and regulations such as GDPR and HIPAA that require strict controls to protect sensitive information. [1]

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-55125. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart