Back to News & Press

Press Release

Searchlight Cyber Uncovers High Severity Remote Code Execution Vulnerability in Popular Survey Software

Share on social

July 16, 2025

Lorem ipsum

Table of contents

Share on social

Join the newsletter
Searchlight Cyber Uncovers High Severity Remote Code Execution Vulnerability in Popular Survey Software

Users of the Lighthouse Studio survey software should update to the latest version urgently

Brisbane, Australia, July 16, 2025

The Assetnote Security Research Team at Searchlight Cyber has published the details of a Remote Code Execution (RCE) vulnerability it discovered in the popular survey software Lighthouse Studio, developed by Sawtooth Software. The vulnerability CVE-2025-34300 was reported to the company in April 2025 and has been patched in Version 9.16.14.

Lighthouse Studio is a survey software widely used by enterprises and often hosted on-premise. The security researchers uncovered the template injection vulnerability in the Perl CGI scripts, which are uploaded to a company’s website to allow users to take the survey. This vulnerability would allow an unauthenticated attacker to execute arbitrary commands in the underlying web server via the Lighthouse Studio software. A detailed description of how this critical vulnerability was uncovered can be found on the Assetnote Security Research Center.

The potential impact of this vulnerability is particularly significant, as the scripts lack an auto-update mechanism and are often copied from survey to survey. A single company might have tens or even hundreds of copies of the scripts on their web server. Companies using Lighthouse Studio are urged to manually update to the latest software version (9.16.14) as soon as possible.

Shubham Shah, SVP of Research and Engineering at Searchlight Cyber said: “We were surprised to discover the prevalence of this survey software. For a sense of its popularity, readers can search their email for ‘ciwweb’ - they may be surprised at the number of results. Moreover, the payload we discovered works for almost every ‘in the wild’ version of the software. Many companies are using Lighthouse Studios on-premise, so we urge them to manually update the software to avoid falling victim to exploitation.”

Searchlight Cyber’s security research team continues to perform novel zero-day and N-day security research to ensure maximum coverage and care for its customers’ attack surfaces. All research is integrated into its Attack Surface Management platform, Assetnote, which continuously monitors, detects, and proves the exploitability of exposures before threat actors can use them.

ENDS

About Searchlight Cyber

Searchlight Cyber was founded in 2017 with a mission to stop threat actors from acting with impunity. Its External Cyber Risk Management Platform helps organizations to identify and protect themselves from emerging cybercriminal threats with Attack Surface Management and Threat Intelligence tools designed to separate the signal from the noise. Find out more at www.slcyber.io.

Related Press Releases

Searchlight Cyber Launches Preemptive Threat Exposure Management Platform to Help Organizations Outpace AI-Accelerated Attacks

Press Release

Read press release

August 12, 2026

Searchlight Cyber Launches Preemptive Threat Exposure Management Platform to Help Organizations Outpace AI-Accelerated Attacks

Searchlight Cyber Appoints Paul Ciesielski as Chief Revenue Officer

Press Release

Read press release

June 11, 2026

Searchlight Cyber Appoints Paul Ciesielski as Chief Revenue Officer

Searchlight Cyber Named a Finalist at the 2026 Cyber Risk Awards

Press Release

Read press release

April 27, 2026

Searchlight Cyber Named a Finalist at the 2026 Cyber Risk Awards

Searchlight Cyber Report: Ransomware Groups Claimed Record Number of Victims in 2025 with 30% Annual Increase

Press Release

Read press release

February 17, 2026

Searchlight Cyber Report: Ransomware Groups Claimed Record Number of Victims in 2025 with 30% Annual Increase

Searchlight Cyber Appoints Michael Gianarakis as CEO

Press Release

Read press release

February 4, 2026

Searchlight Cyber Appoints Michael Gianarakis as CEO

Searchlight Cyber Launches Ransomware File Explorer to Enable Pre-Emptive Detection of Leaked Data

Press Release

Read press release

January 22, 2026

Searchlight Cyber Launches Ransomware File Explorer to Enable Pre-Emptive Detection of Leaked Data

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient