
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-54792 is a Man-in-the-Middle (MitM) vulnerability in LocalSend's UDP-based device discovery protocol that allows an unauthenticated attacker on the same local network to impersonate legitimate devices and intercept or modify file transfers. It affects LocalSend versions 1.16.1 and below, and was disclosed on August 1, 2025, with a fix released in version 1.17.0. The vulnerability carries a CVSS v3.1 base score of 6.8 (Medium) and a CVSS v4.0 base score of 9.3 (Critical) (GitHub Advisory, Red Hat CVE).
The root cause lies in LocalSend's use of UDP multicast packets for peer discovery, where the source IP address field in UDP packet headers is not authenticated or verified (CWE-300: Channel Accessible by Non-Endpoint; CWE-345: Insufficient Verification of Data Authenticity). When a device receives a discovery packet, it trusts the sender's claimed IP and device information without any cryptographic verification, adding the peer to the UI for file transfers. An attacker on the same network can trivially spoof the source IP in UDP discovery packets to impersonate any legitimate device — including devices saved in a user's "Favorites" list — causing victims to unknowingly send files to the attacker's machine. A proof-of-concept demonstrating the attack (including a GIF walkthrough) was published in the GitHub Security Advisory (GitHub Advisory).
Successful exploitation allows an attacker to silently intercept all files and messages sent between LocalSend users on the same network, fully compromising the confidentiality and integrity of transferred data. Beyond passive interception, the attacker can modify files in transit to embed malicious payloads such as ransomware, spyware, or trojans, which are then delivered to the recipient appearing to originate from a trusted source. Because the attacker can also forge the sender field of packets, the compromised file reaches the intended recipient, making it highly likely the victim will open it and potentially leading to arbitrary code execution and persistent compromise of the recipient's device (GitHub Advisory).
A proof-of-concept exploit (including a demonstration GIF) is publicly available in the GitHub Security Advisory, showing a practical attack scenario where a legitimate file transfer is intercepted and redirected to the attacker's machine. There is no evidence of in-the-wild exploitation at this time, and the CVE is not listed in the CISA KEV catalog. The EPSS score is approximately 0.01%, reflecting low current exploitation probability. The attack requires the attacker to be on the same local network (e.g., shared Wi-Fi), requires no authentication or privileges, and is described as easy to implement and difficult to detect (GitHub Advisory).
The primary remediation is to upgrade LocalSend to version 1.17.0 or later, which addresses the path traversal component and includes security fixes (LocalSend v1.17.0). The fix commit (e8635204) implements TCP handshake-based IP address verification to prevent UDP source IP spoofing in the discovery protocol (GitHub Commit). As interim workarounds, users should avoid using LocalSend on untrusted or shared networks, manually verify device identities before transferring sensitive files, and apply additional encryption to critical file transfers (GitHub Advisory).
The vulnerability was reported by security researcher DeePunk42 and published by LocalSend maintainer Tienisto on August 1, 2025. A Mastodon post referencing the vulnerability was noted in community feeds. Red Hat tracked the CVE in their security database. No major media coverage or significant public researcher commentary beyond the GitHub advisory has been identified at this time (GitHub Advisory, Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."