CVE-2025-34282
ThingsBoard < v4.2.1 SVG Image SSRF
Vexday Risk Score
33Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 6.9EPSS 1.7%KEV nãoPoC públicaNuclei —Metasploit —Patch referenciado
Lifecycle
17 Oct 2025Published on NVD
26 Mar 2026Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload Gallery feature. An attacker can upload a malicious SVG file that references a remote URL. If the server processes the SVG file in a way that parses external references, it may initiate unintended outbound requests. This can be used to access internal services or resources.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L
Affected products
ThingsBoard, Inc. · ThingsBoardpublic PoCs found — 2
githubgithub.com/mathitam/thingsboard-ssrf-cve-2025-34282★ 0exploitdbwww.exploit-db.com/exploits/52551unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →