PT-2025-28396 · Sinec Nms · Sinec Nms

Published

2025-07-08

·

Updated

2025-07-09

·

CVE-2025-40738

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: SINEC NMS versions prior to V4.0
Description: A security issue has been identified in the affected application, where it does not properly validate file paths when extracting uploaded ZIP files. This could allow an attacker to write arbitrary files to restricted locations and potentially execute code with elevated privileges.
Recommendations: For versions prior to V4.0, update to version V4.0 or later to resolve the issue. As a temporary workaround, consider restricting the upload of ZIP files or implementing additional validation on file paths to minimize the risk of exploitation.

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2025-08985
CVE-2025-40738
ZDI-25-576

Affected Products

Sinec Nms