PT-2025-37013 · Welotec · Smartems Web Application

Published

2025-09-10

·

Updated

2025-09-15

·

CVE-2025-41714

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: versions prior to 2025-41714
Description: The upload endpoint does not adequately validate the Upload-Key request header. An authenticated attacker can use path traversal sequences within the header to create files outside the intended storage location. In some configurations, this can lead to arbitrary file write and potentially remote code execution.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-41714

Affected Products

Smartems Web Application