CVE-2025-55056
Rumpus vulnerability analysis and mitigation

Overview

CVE-2025-55056 is a Cross-Site Scripting (XSS) vulnerability affecting Maxum Rumpus FTP Server version 9.0.12. The vulnerability involves multiple instances of improper neutralization of input during web page generation (CWE-79), allowing high-privileged users to inject malicious scripts via network access. It was published on November 17, 2025. The CVSS v3.1 base score is estimated at 6.1 (Medium) by Feedly, while ENISA's EUVD rates it at 4.8 (Medium) with a vector requiring high privileges (Feedly, EUVD).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), with multiple XSS instances present in the Rumpus web interface. The attack vector is network-based, requiring user interaction (e.g., a victim visiting or interacting with a crafted page) and, per the ENISA scoring, high privileges to inject the malicious payload. The vulnerability has a changed scope, meaning the injected scripts can affect resources beyond the vulnerable component itself, such as the victim's browser session. No public proof-of-concept code or detailed technical write-ups have been identified at this time (Feedly, EUVD).

Impact

Successful exploitation could allow an attacker with administrative access to inject malicious scripts into the Rumpus web interface, potentially compromising user sessions, stealing session cookies or credentials, and performing unauthorized actions on behalf of victims. The confidentiality and integrity impacts are rated as low, with no direct availability impact. The changed scope indicates that the attack can affect users beyond the directly vulnerable component, increasing the risk of data exposure across the application (Feedly).

Mitigation and workarounds

Users running Maxum Rumpus FTP Server version 9.0.12 should monitor the vendor's official website for a patched release and apply updates as soon as they become available. In the interim, restricting access to the Rumpus web administration interface to trusted IP addresses and enforcing strong authentication controls can reduce exposure. Disabling or limiting web-based administrative access where not required is also advisable (Feedly, EUVD).

Additional resources


SourceThis report was generated using AI

Related Rumpus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-55058CRITICAL9.8
  • Rumpus logoRumpus
  • cpe:2.3:a:maxum:rumpus
NoNoNov 17, 2025
CVE-2025-55055CRITICAL9.8
  • Rumpus logoRumpus
  • cpe:2.3:a:maxum:rumpus
NoNoNov 17, 2025
CVE-2025-55057HIGH8.8
  • Rumpus logoRumpus
  • cpe:2.3:a:maxum:rumpus
NoNoNov 17, 2025
CVE-2025-55059MEDIUM6.1
  • Rumpus logoRumpus
  • cpe:2.3:a:maxum:rumpus
NoNoNov 17, 2025
CVE-2025-55056MEDIUM6.1
  • Rumpus logoRumpus
  • cpe:2.3:a:maxum:rumpus
NoNoNov 17, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management