PT-2025-25657 · Zendto · Zendto

Horizon3.Ai

·

Published

2025-04-15

·

Updated

2025-09-25

·

CVE-2025-34508

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ZendTo versions 6.15 through 7 ZendTo version 6.15-8 (fixed version)
Description A path traversal vulnerability exists in the file dropoff functionality of ZendTo. This flaw allows attackers to bypass security controls to access or modify sensitive information of other users, retrieve files on the host system, or cause a denial of service. The vulnerability arises from insufficient validation of user input, specifically the chunkName and tmp name parameters, during file processing.
Recommendations ZendTo versions prior to 6.15-8: Upgrade to version 6.15-8 or later to address this vulnerability.

Exploit

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2025-07026
CVE-2025-34508

Affected Products

Zendto