References https://nvd.nist.gov/vuln/detail/CVE-2025-49493 https://github.com/SystemVll/CVE-2025-49493 https://www.tenable.com/cve/CVE-2025-49493 https://xbow.com/blog/xbow-akamai-cloudtest-xxe https://techdocs.akamai.com/cloudtest/changelog/june-2-2025-enhancements-and-bug-fixes/ https://www.cve.org/CVERecord?id=CVE-2025-49493 https://github.com/advisories/GHSA-g536-463c-q7r3 https://sploitus.com/exploit?id=006DE3B1-1DD0-5F5A-A5EB-3317056C5CC3 https://www.akamai.com/products/cloudtest
Related VulnerabilitiesPoCCVE-2025-51683: mJobTime <= 15.7.2 - Unauthenticated Blind SQL Injection to RCEPoCCVE-2025-57231: Docmost 0.2.1-0.21.0 - Arbitrary File ReadWordpress Events Calendar插件敏感信息泄露漏洞(CVE-2025-9808)WordPress Directory Kit 插件敏感信息泄露漏洞(CVE-2025-13920)PoCCVE-2025-53887: Directus < 11.9.0 - Version DisclosurePoCCVE-2025-14047: User Frontend <= 4.2.4 - Missing Authorization to Unauthenticated Attachment DeletionPoCCVE-2025-14998: Branda WordPress plugin - Privilege EscalationPoCCVE-2025-15403: RegistrationMagic <= 6.0.7.1 - Privilege EscalationPoCCVE-2025-0520: ShowDoc - Remote Code ExecutionPoCCVE-2025-26399: SolarWinds Web Help Desk < 12.8.7 - AjaxProxy Deserialization RCEPoCCVE-2025-11953: React Native Community CLI - Unauthenticated OS Command InjectionPoCCVE-2025-13342: DynamiApps Frontend Admin <= 3.28.20 - Unauthenticated Arbitrary Options UpdatePoCCVE-2025-13528: Feedback Modal for Website <= 1.0.1 - Unauthenticated Feedback Export