
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-55055 is an OS Command Injection vulnerability (CWE-78) affecting Maxum Rumpus FTP Server version 9.0.12. It involves improper neutralization of special elements used in OS commands, potentially allowing attackers to execute arbitrary system commands. The vulnerability was published on November 17, 2025. It carries a CVSS v3.1 base score of 9.8 (Critical) per NVD, though ENISA's EU Vulnerability Database assigns a score of 6.8 (Medium) with a vector requiring high privileges and user interaction (Feedly, CIRCL).
The vulnerability is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command), meaning user-supplied input is not properly sanitized before being passed to OS-level command execution functions in Maxum Rumpus 9.0.12. The discrepancy between NVD's CVSS score (9.8, no privileges required) and ENISA's score (6.8, high privileges required, user interaction needed) suggests uncertainty about the exact attack preconditions — the ENISA vector implies exploitation may require an authenticated administrative session. No technical write-ups or public proof-of-concept code have been identified at this time (Feedly, CIRCL).
Successful exploitation could allow an attacker to execute arbitrary OS commands on the host running Maxum Rumpus, potentially achieving full system compromise. The impacts span confidentiality (access to sensitive data), integrity (modification of system files or configurations), and availability (disruption of FTP services or the underlying host). Given that Rumpus is an FTP server, exploitation could expose file transfer data, credentials, and hosted files to unauthorized parties (Feedly).
No official patch has been confirmed as available for Maxum Rumpus 9.0.12 at the time of publication. Organizations should restrict administrative access to the Rumpus FTP server to trusted personnel only and apply the principle of least privilege for all administrative accounts. Network segmentation should be used to limit exposure of the affected system, and suspicious command execution patterns on the host should be actively monitored. Users should monitor Maxum's official channels for patch releases and apply updates immediately upon availability (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."