PT-2025-39168 · Inka.Net · Inka.Net

Published

2025-09-23

·

Updated

2025-09-24

·

CVE-2025-9846

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Inka.Net versions prior to 6.7.1
Description A flaw exists in Inka.Net that allows for command injection through the unrestricted upload of files with dangerous types. This issue could potentially allow an attacker to execute arbitrary commands on the system.
Recommendations Update Inka.Net to version 6.7.1 or later.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-9846

Affected Products

Inka.Net