All findings

CVE-2025-54322 critical

pwn.ai reports unauthenticated root RCE in XSpeeder SXZOS

pwn.ai says its autonomous platform found an unauthenticated command-injection path yielding root execution in XSpeeder SXZOS; the public CVE record corroborates the vulnerability.

Bug class
Unauthenticated OS command injection and root code execution
Affected codebase
XSpeeder SXZOS
Credited system
pwn.ai
Disclosed
July 22, 2025
Attribution
Self-reported attribution
Severity
critical
Source status: pwn.ai provides the autonomous discovery claim, technical analysis, and proof of concept. The public CVE record independently corroborates the unauthenticated root command injection.

Summary

The vulnerability allowed an unauthenticated network attacker to inject shell commands into an SXZOS management request and execute them as root. pwn.ai published a proof of concept and reported broad internet exposure.

Attribution

The underlying vulnerability is CVE-backed, but the autonomous-discovery claim comes from pwn.ai. The entry is therefore labeled self-reported rather than direct vendor attribution.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.