PT-2025-48394 · Scada-Lts · Scada-Lts

Sh7Err02

+1

·

Published

2025-11-06

·

Updated

2025-11-30

·

CVE-2025-13791

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Scada-LTS versions prior to 2.7.8.1
Description A path traversal issue exists in Scada-LTS. The Common.getHomeDir function within the br/org/scadabr/vo/exporter/ZIPProjectManager.java file of the Project Import component is affected. This manipulation can be exploited remotely. The exploit is publicly available.
Recommendations Update Scada-LTS to version 2.7.8.1 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-14906
CVE-2025-13791

Affected Products

Scada-Lts