PT-2025-30725 · Unknown · Zhousg Letao

Zast.Ai

·

Published

2025-07-25

·

Updated

2025-07-25

·

CVE-2025-8128

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions zhousg letao (affected versions not specified)
Description A critical vulnerability exists in zhousg letao due to unrestricted file upload. The issue stems from improper processing of file routesbfproduct.js, specifically through manipulation of the pictrdtz argument. This allows for unrestricted uploads and can be initiated remotely. The exploit has been publicly disclosed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-8128

Affected Products

Zhousg Letao