CVE-2025-27234

EUVD-2025-29036
Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. In Zabbix 5.0 this allows for remote code execution.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
ZabbixCNA
7.3 HIGH
ADJACENT
LOW
HIGH
CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 24.07%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
zabbixzabbix
5.0.0 ≤
𝑥
≤ 5.0.46
CNA
Debian logo
Debian Releases
Debian Product
Codename
zabbix
bookworm
1:6.0.14+dfsg-1
fixed
bullseye
vulnerable
bullseye (security)
1:5.0.47+dfsg-0+deb11u1
fixed
sid
1:7.0.22+dfsg-1.1
fixed
trixie
1:7.0.22+dfsg-1~deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
zabbix
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
plucky
not-affected
questing
not-affected
resolute
not-affected
trusty
needs-triage
xenial
needs-triage