Metrics
Affected Vendors & Products
No advisories yet.
Solution
The vulnerability has been fixed in version V3.06.38.
Workaround
No workaround given by the vendor.
Thu, 26 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Mar 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-428 |
Thu, 26 Mar 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable located at 'C:\Program Files (x86)\shttps_mg\http.exe service'. This misconfiguration allows a local attacker to place a malicious executable with the same name in a higher priority directory, causing the service to execute the malicious file instead of the legitimate one. Exploiting this flaw could allow arbitrary code execution, unauthorized access to the system, or service disruption. To mitigate the risk, the service path must be properly quoted, and systems must be kept up to date with security patches, while restricting physical and network access. | Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote users to bypass the intended restrictions of SecurityManager and display any file if they have the appropriate permissions outside the document root configured on the server. |
| Weaknesses | CWE-22 | |
| Metrics |
cvssV4_0
|
cvssV4_0
|
Thu, 26 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable located at 'C:\Program Files (x86)\shttps_mg\http.exe service'. This misconfiguration allows a local attacker to place a malicious executable with the same name in a higher priority directory, causing the service to execute the malicious file instead of the legitimate one. Exploiting this flaw could allow arbitrary code execution, unauthorized access to the system, or service disruption. To mitigate the risk, the service path must be properly quoted, and systems must be kept up to date with security patches, while restricting physical and network access. | |
| Title | Multiple vulnerabilities in Small HTTP server by Smallsrv | |
| First Time appeared |
Smallsrv
Smallsrv small Http |
|
| Weaknesses | CWE-428 | |
| CPEs | cpe:2.3:a:smallsrv:small_http:3.06.36:*:*:*:*:*:*:* | |
| Vendors & Products |
Smallsrv
Smallsrv small Http |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-03-26T13:40:20.561Z
Reserved: 2025-04-16T09:57:06.080Z
Link: CVE-2025-41368
Updated: 2026-03-26T13:40:16.762Z
Status : Awaiting Analysis
Published: 2026-03-26T12:16:08.583
Modified: 2026-03-26T15:13:15.790
Link: CVE-2025-41368
No data.
OpenCVE Enrichment
Updated: 2026-03-26T13:54:50Z