CVE-2025-55057
Rumpus vulnerability analysis and mitigation

Overview

CVE-2025-55057 describes multiple Cross-Site Request Forgery (CSRF) vulnerabilities affecting Maxum Rumpus version 9.0.12, an FTP server application. The vulnerabilities allow network-based attackers to trick authenticated users into performing unauthorized actions without their knowledge or consent. Published on November 17, 2025, and assigned by INCD (Israel National Cyber Directorate), the CVE carries a CVSS v3.1 base score of 8.8 (High) per NVD scoring, though ENISA's EUVD rates it at 4.5 under a more restrictive scoring vector (Feedly, CIRCL).

Technical details

The root cause is classified as CWE-352 (Cross-Site Request Forgery), where the application fails to verify that state-changing requests originate from legitimate, authenticated user sessions. An attacker crafts a malicious web page or link that, when visited by an authenticated Rumpus user, silently submits forged HTTP requests to the server on the user's behalf. Exploitation requires no authentication or special privileges from the attacker, only that the victim is logged into the Rumpus application and interacts with attacker-controlled content. No public proof-of-concept or detailed technical write-up has been identified at this time (Feedly).

Impact

Successful exploitation can result in high impact to confidentiality, integrity, and availability of the affected Rumpus FTP server instance. Attackers can cause authenticated users to unknowingly perform unauthorized administrative or file management actions — such as modifying configurations, uploading/deleting files, or altering user accounts — without the victim's consent. The scope is limited to the affected application instance, but compromise of an FTP server's administrative functions could expose sensitive data or disrupt file transfer services (Feedly).

Exploitation steps

  1. Reconnaissance: Identify a target running Maxum Rumpus 9.0.12, particularly its web-based administration or user interface, accessible over the network.
  2. Craft malicious request: Construct an HTML page or link containing a forged HTTP request (e.g., a hidden form or image tag) targeting a state-changing endpoint in the Rumpus web interface, such as a user management or file operation action.
  3. Deliver payload: Trick an authenticated Rumpus user (e.g., an administrator) into visiting the malicious page via phishing email, social engineering, or a compromised website.
  4. Trigger forged action: When the victim's browser loads the attacker's page, it automatically submits the forged request to the Rumpus server using the victim's active session cookies, causing the server to execute the unauthorized action.
  5. Achieve objective: Depending on the targeted endpoint, the attacker may modify server configurations, manipulate user accounts, upload or delete files, or otherwise compromise the FTP server's integrity (Feedly).

Indicators of compromise

  • Logs: Unexpected state-changing requests (POST/GET to administrative or file management endpoints) in Rumpus access logs originating from authenticated sessions at unusual times or from unexpected IP addresses.
  • Application Behavior: Unexplained changes to user accounts, server configurations, or file system contents within the Rumpus-managed directories.
  • Network: HTTP requests to Rumpus administrative endpoints with referrer headers pointing to external or unknown domains, which may indicate cross-origin request forgery attempts.

Mitigation and workarounds

Patch availability for Maxum Rumpus 9.0.12 is currently unknown; administrators should monitor the Maxum website for security updates and apply any available patches promptly. As interim mitigations, implement CSRF tokens (anti-CSRF tokens) on all state-changing requests within the application, enforce SameSite=Strict or SameSite=Lax cookie attributes to restrict cross-site cookie transmission, and validate Origin and Referer headers on sensitive operations. Additionally, restrict access to the Rumpus web administration interface to trusted networks or VPN, and educate users about the risks of clicking untrusted links while authenticated (Feedly).

Additional resources


SourceThis report was generated using AI

Related Rumpus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-55058CRITICAL9.8
  • Rumpus logoRumpus
  • cpe:2.3:a:maxum:rumpus
NoNoNov 17, 2025
CVE-2025-55055CRITICAL9.8
  • Rumpus logoRumpus
  • cpe:2.3:a:maxum:rumpus
NoNoNov 17, 2025
CVE-2025-55057HIGH8.8
  • Rumpus logoRumpus
  • cpe:2.3:a:maxum:rumpus
NoNoNov 17, 2025
CVE-2025-55059MEDIUM6.1
  • Rumpus logoRumpus
  • cpe:2.3:a:maxum:rumpus
NoNoNov 17, 2025
CVE-2025-55056MEDIUM6.1
  • Rumpus logoRumpus
  • cpe:2.3:a:maxum:rumpus
NoNoNov 17, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management