PT-2025-28396 · Sinec Nms · Sinec Nms

CVE-2025-40738

·

Publicado

2025-07-08

·

Atualizado

2025-07-09

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: SINEC NMS versions prior to V4.0
Description: A security issue has been identified in the affected application, where it does not properly validate file paths when extracting uploaded ZIP files. This could allow an attacker to write arbitrary files to restricted locations and potentially execute code with elevated privileges.
Recommendations: For versions prior to V4.0, update to version V4.0 or later to resolve the issue. As a temporary workaround, consider restricting the upload of ZIP files or implementing additional validation on file paths to minimize the risk of exploitation.

Correção

RCE

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-08985
CVE-2025-40738
ZDI-25-576

Produtos afetados

Sinec Nms