PT-2025-38660 · Unknown · Seriawei Zkeacms

Yu Bao

·

Published

2025-09-21

·

Updated

2025-09-21

·

CVE-2025-10766

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SeriaWei ZKEACMS versions prior to 4.4
Description A weakness has been identified in SeriaWei ZKEACMS that allows for path traversal through manipulation of the ID argument in the Download function of the EventViewerController.cs file. This issue is remotely exploitable. The exploit has been made publicly available. The vendor was contacted but did not respond.
Recommendations Update SeriaWei ZKEACMS to version 4.4 or later. As a temporary workaround, restrict access to the Download function within the EventViewerController.cs file. Avoid using the ID parameter in the Download function until the issue is resolved.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-10766

Affected Products

Seriawei Zkeacms