Vulnerability Description
In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed by any digit string, then an attacker can login with any other string that evaluates to 0.0 (such as the 0e0 string). This occurs in admin/plib/LoginManager.php.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://blog.aziz.tn/2025/08/cve-2025-54336.html/
- https://support.plesk.com/hc/en-us/articles/33785727869847-Vulnerability-CVE-202
- https://www.plesk.com/blog/plesk-news-announcements/introducing-plesk-obsidian-1
FAQ
What is CVE-2025-54336?
CVE-2025-54336 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed by any digit string, then an attacker can login with any other string that evalua...
How severe is CVE-2025-54336?
CVE-2025-54336 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-54336?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.