
One Byte Is Plenty: Reversing IceWarp CVE-2025-14500
IceWarp's X-File-Operation RCE (CVE-2025-14500) is really a missing null-byte check in the FastCGI parameter builder. One null byte in a request is enough for unauthenticated code execution as root.