---
title: "CVE-2025-63261\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2025-63261?format=md
keywords: index, follow
---

# CVE-2025-63261

Publication date 20 March 2026

Last updated 2 April 2026

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/CVE-2025-63261?format=md#priority-reason )

## Cvss 3 Severity Score

**7.8 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2025-63261?format=md#impact-score)

Toggle side navigation

## Description

AWStats 8.0 is vulnerable to Command Injection via the open function

[Read the notes from the security team](https://ubuntu.com/security/CVE-2025-63261?format=md#notes)

### Why is this CVE low priority?

This requires access to modify awstats.conf

[Learn more about Ubuntu priority](https://ubuntu.com/security/cves/about#priority)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| awstats | 26.04 LTS resolute | Needs evaluation |
| 25.10 questing | Ignored end of life, was needs-triage |
| 24.04 LTS noble | Needs evaluation |
| 22.04 LTS jammy | Needs evaluation |
| 20.04 LTS focal | Needs evaluation |
| 18.04 LTS bionic | Needs evaluation |
| 16.04 LTS xenial | Needs evaluation |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

This vulnerability requires a user to be able to modify the
awstats.conf configuration file. Only the root user is able to
modify the file in Ubuntu, so this is an unlikely attack
scenario. Setting this issue to low priority.

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.8 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.8 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-63261)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-63261)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2025-63261)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2025-63261)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2025-63261>
* <https://github.com/eldy/AWStats/blob/develop/wwwroot/cgi-bin/awstats.pl>
* <https://pentest-tools.com/PTT-2025-021-Code-Execution-in-AWStats.pdf>
