Improper access control in AzuraCast - CVE-2025-67737
Published: April 23, 2026
AzuraCast
Detailed vulnerability description
The vulnerability allows a remote attacker to modify station database contents.
The vulnerability exists due to improper access control in the internal sftp-event API endpoint when handling crafted HTTP requests to the public-facing API. A remote attacker can send a specially crafted request to modify station database contents.
User interaction is required, and exploitation requires knowledge of a valid SFTP username and the station's internal filesystem path structure.