1.
An accidental find: Traccar v5.8-v6.8.1 on Windows has an unauthenticated LFI (CVE-2025-61666) because a servlet bypasses Jetty's path checks. The post reads configs with LDAP passwords.
Skip to content
Curated 1 security research writeups, vulnerability advisories and exploitation analyses for CVE-2025-61666.