PT-2025-30725 · Unknown · Zhousg Letao
Zast.Ai
·
Published
2025-07-25
·
Updated
2025-07-25
·
CVE-2025-8128
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
zhousg letao (affected versions not specified)
Description
A critical vulnerability exists in zhousg letao due to unrestricted file upload. The issue stems from improper processing of file routesbfproduct.js, specifically through manipulation of the
pictrdtz argument. This allows for unrestricted uploads and can be initiated remotely. The exploit has been publicly disclosed.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Access Control
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zhousg Letao