PT-2025-28396 · Sinec Nms · Sinec Nms
Published
2025-07-08
·
Updated
2025-07-09
·
CVE-2025-40738
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
SINEC NMS versions prior to V4.0
Description:
A security issue has been identified in the affected application, where it does not properly validate file paths when extracting uploaded ZIP files. This could allow an attacker to write arbitrary files to restricted locations and potentially execute code with elevated privileges.
Recommendations:
For versions prior to V4.0, update to version V4.0 or later to resolve the issue. As a temporary workaround, consider restricting the upload of ZIP files or implementing additional validation on file paths to minimize the risk of exploitation.
Fix
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sinec Nms