OS Command InjectionWeakness · CWE-78

CVE-2025-34160

CRITICAL · 10.0 CVSS v4.0 Published 2025-08-27
Mitigation only
No fix yet — a mitigation exists. There is no fixed release. A documented workaround reduces exposure in the meantime.
See remediation →
100/100
Remediation priority · Urgent
Remotely reachable No privileges Zero-click

Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.

NVD · unedited
AnyShare contains a critical unauthenticated remote code execution vulnerability in the ServiceAgent API exposed on port 10250. The endpoint /api/ServiceAgent/start_service accepts user-supplied input via POST and fails to sanitize command-like payloads. An attacker can inject shell syntax that is interpreted by the backend, enabling arbitrary command execution. The vulnerability is presumed to affect builds released prior to August 2025 and is said to be remediated in newer versions of the product, though the exact affected range remains undefined. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-07-11 UTC.

Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.

dbcve analysis · high confidence

AnyShare contains an unauthenticated remote code execution vulnerability in the ServiceAgent API exposed on port 10250. The endpoint /api/ServiceAgent/start_service accepts user-supplied input via POST without sanitization, allowing attackers to inject shell syntax that is interpreted by the backend, enabling arbitrary command execution with the privileges of the service account.

MitigationUpgrade AnyShare to a version released August 2025 or later. As a compensating control, restrict network access to port 10250 to trusted internal systems only until the upgrade can be completed.

Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.

CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.

From the vector
Attack vector
Network
Complexity
Low
Privileges
None
Authentication
X
User interaction
None
Scope
X

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.

dbcve checks

Work through these to decide whether this CVE applies to you.

  1. Identify AnyShare installation and version
    Locate the AnyShare installation directory and check the version file or binary version information. Common paths may include /opt/AnyShare or similar. Use commands like 'ls -la' on potential installation directories or check for version info in any configuration files.
    Affected if AnyShare version is present but the version is earlier than the August 2025 release
  2. Verify port 10250 is listening
    Run 'netstat -tulpn | grep 10250' or 'ss -tulpn | grep 10250' to check if port 10250 is open and bound to a service process.
    Affected if Port 10250 is open and listening, indicating the ServiceAgent API is exposed
  3. Confirm ServiceAgent API endpoint availability
    Send a HTTP request to http://<target>:10250/api/ServiceAgent/start_service using curl or similar tool. A valid response (even an error) indicates the endpoint exists.
    Affected if The endpoint responds with any HTTP status, confirming the vulnerable API is accessible
  4. Check network accessibility of port 10250
    From an external host, verify the port is reachable. Use 'nc -zv <target> 10250' or a port scanner to determine if the port is exposed to untrusted networks.
    Affected if Port 10250 is accessible from untrusted network segments or the internet
  5. Compare installed version to fixed release
    Document the exact AnyShare version number found in step 1 and compare it against the August 2025 release date. Earlier versions are considered affected.
    Affected if The installed AnyShare version predates the August 2025 release and port 10250 is accessible

A user is affected if AnyShare is running with a version released before August 2025 AND the ServiceAgent API on port 10250 is exposed and accessible.

Generated from the published advisory. Verify against your own configuration.

Check your environment

Paste your version and any relevant configuration and it will be compared against the affected criteria above. Do not include secrets or credentials.

AI-assisted, checked against the advisory. Informational, not a guarantee.

Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.

dbcve · scoped
Mitigation available No clean upgrade yet — mitigate in the meantime
Mitigation

Upgrade AnyShare to a version released August 2025 or later. As a compensating control, restrict network access to port 10250 to trusted internal systems only until the upgrade can be completed.

Recommended fix Moderate confidence

AnyShare version/build released after August 2025 (contact vendor for exact version number)

  1. Identify all AnyShare installations in the environment and confirm the specific version/build number of each instance
  2. If running AnyShare builds prior to August 2025, obtain and apply the latest stable release from the vendor that includes the remediation for CVE-2025-34160
  3. After upgrading, verify that the /api/ServiceAgent/start_service endpoint on port 10250 no longer accepts unauthenticated command injection payloads
  4. If immediate upgrade is not feasible, implement network-level controls to restrict access to port 10250 to only trusted IP addresses or internal management networks
  5. Confirm with vendor documentation that the specific build applied includes the patch for this vulnerability

Generated from the published advisory — verify against the referenced sources before acting.

Have this fixed Scoped from the published advisory
  • Consultation4.0 h
  • Implementation8.0 h
  • Testing4.0 h
  • Review / QA2.0 h
18.0 hours of engineering $3,200
Get help mitigating

An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $5,120.

Scan for this in your stack

Free · runs locally
dbcve dependency scanner

Check whether your project pulls in CVE-2025-34160 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.

References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.

Primary sources

Practitioner notes

Contributed

Peer-ranked notes from engineers who’ve handled CVE-2025-34160 in production — separate from our analysis above.

No notes yet

Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.

What this is

A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.

What belongs here
  • Verified mitigations, workarounds, and config changes
  • Version or environment caveats, and links to real fixes
  • No weaponised exploit code, or anything meant to cause harm
  • No spam, self-promotion, credentials, or personal data