PT-2025-29881 · Linknat · Linknat Vos3000+2

Zqsky

·

Publicado

2025-07-16

·

Atualizado

2025-07-17

·

CVE-2025-34118

CVSS v4.0

8.7

Alta

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Linknat VOS Manager versions prior to 2.1.9.07 Linknat VOS2009 Linknat VOS3000 (early builds)
Description A path traversal issue exists in Linknat VOS Manager that allows unauthenticated remote attackers to read arbitrary files on the server. The vulnerability is accessible via multiple localized subpaths, such as '/eng/', '/chs/', or '/cht/', where files like 'js/lang en us.js' or their equivalents are loaded. Attackers can bypass input validation and disclose sensitive files by injecting encoded traversal sequences, such as '%c0%ae%c0%ae', into the request path.
Recommendations Update Linknat VOS Manager to version 2.1.9.07 or later. Update Linknat VOS2009 to a newer version. Update Linknat VOS3000 to a newer build.

Exploit

Correção

RCE

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-34118

Produtos afetados

Linknat Vos Manager
Linknat Vos2009
Linknat Vos3000