CVE-2025-34429: CWE-352 Cross-Site Request Forgery (CSRF) in LXware 1Panel
1Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the web port configuration functionality. The port-change endpoint lacks CSRF defenses such as anti-CSRF tokens or Origin/Referer validation. An attacker can craft a malicious webpage that submits a port-change request; when a victim visits it while authenticated, the browser includes valid session cookies and the request succeeds. This allows an attacker to change the port on which the 1Panel web service listens, causing loss of access on the original port and resulting in service disruption or denial of service, and may unintentionally expose the service on an attacker-chosen port.
AI Analysis
Technical Summary
CVE-2025-34429 is a CSRF vulnerability affecting LXware 1Panel versions 1.10.33 to 2.0.15. The port-change endpoint lacks anti-CSRF tokens and does not validate Origin or Referer headers, enabling attackers to craft malicious webpages that submit unauthorized port-change requests on behalf of authenticated users. This can disrupt service availability by changing the listening port or expose the service on a port chosen by the attacker.
Potential Impact
Exploitation allows an attacker to cause denial of service by changing the web service port, resulting in loss of access on the original port. Additionally, the service may become accessible on an attacker-specified port, potentially increasing exposure. There is no indication of privilege escalation or data compromise beyond service disruption and exposure.
Mitigation Recommendations
No official patch or fix is currently available. Users should monitor the vendor advisory for updates. In the meantime, restricting access to the 1Panel interface to trusted networks and avoiding visiting untrusted webpages while authenticated may reduce risk. Implementing external protections such as web application firewalls that enforce CSRF protections could also help mitigate exploitation.
CVE-2025-34429: CWE-352 Cross-Site Request Forgery (CSRF) in LXware 1Panel
Description
1Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the web port configuration functionality. The port-change endpoint lacks CSRF defenses such as anti-CSRF tokens or Origin/Referer validation. An attacker can craft a malicious webpage that submits a port-change request; when a victim visits it while authenticated, the browser includes valid session cookies and the request succeeds. This allows an attacker to change the port on which the 1Panel web service listens, causing loss of access on the original port and resulting in service disruption or denial of service, and may unintentionally expose the service on an attacker-chosen port.
CVSS v4.0
Score 7.0high
Affected software
pkg:github/1panel-dev/1PanelRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-34429 is a CSRF vulnerability affecting LXware 1Panel versions 1.10.33 to 2.0.15. The port-change endpoint lacks anti-CSRF tokens and does not validate Origin or Referer headers, enabling attackers to craft malicious webpages that submit unauthorized port-change requests on behalf of authenticated users. This can disrupt service availability by changing the listening port or expose the service on a port chosen by the attacker.
Potential Impact
Exploitation allows an attacker to cause denial of service by changing the web service port, resulting in loss of access on the original port. Additionally, the service may become accessible on an attacker-specified port, potentially increasing exposure. There is no indication of privilege escalation or data compromise beyond service disruption and exposure.
Mitigation Recommendations
No official patch or fix is currently available. Users should monitor the vendor advisory for updates. In the meantime, restricting access to the 1Panel interface to trusted networks and avoiding visiting untrusted webpages while authenticated may reduce risk. Implementing external protections such as web application firewalls that enforce CSRF protections could also help mitigate exploitation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2025-04-15T19:15:22.601Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6939bda4fe7b3954b690add5
Added to database: 12/10/2025, 18:36:20 UTC
Last enriched: 07/15/2026, 09:53:25 UTC
Last updated: 09/10/2026, 19:36:50 UTC
Views: 193
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.