PT-2025-24614 · Zendto · Zendto

·

CVE-2025-5952

·

Published

2025-06-10

·

Updated

2025-06-17

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Zend.To versions 6.10-6 Beta and earlier
Description A critical vulnerability has been found in Zend.To, affecting the function exec of the file NSSDropoff.php. The manipulation of the argument file 1 leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This issue affects a rather old version of the software. The vendor recommends updating to the latest release.
Recommendations To address this issue, upgrade to version 6.10-7 or later. As a temporary workaround, consider disabling the exec function in the NSSDropoff.php file until a patch is available. Restrict access to the vulnerable file to minimize the risk of exploitation. Avoid using the file 1 argument in the affected function until the issue is resolved.

Exploit

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-5952

Affected Products

Zendto