[CVE-2025-61666] Traccar Unauthenticated LFI v5.8-v6.8.1
projectblack.io | research | CVE-2025-61666 | #lfi | #unauthenticated | #traccar | #cve-2025-61666 | #jetty
Summary
An accidental find: Traccar v5.8-v6.8.1 on Windows has an unauthenticated LFI (CVE-2025-61666) because a servlet bypasses Jetty's path checks. The post reads configs with LDAP passwords.
- Published
- Collected
Skip to content