CVE-2025-14602: Weak File Name Generation in vsDesk
The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to accurately guess or brute-force the generated filename within a short time window. An attacker can successfully locate and access uploaded files, which can be used to facilitate further attacks.
Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
vsDeskto a version that resolves this vulnerability.Fixed in 14.0101
Event History
Frequently Asked Questions
Which deployments require remediation?
vsDesk versions before 14.0101 require remediation. Versions 14.0101 and later include the vendor patch.
What does an attacker need to exploit this issue?
An attacker needs remote access to the application and the ability to predict or brute-force upload-generated filenames within a short time window. The filenames are derived from the request timestamp.
What is the likely impact if exploitation succeeds?
An attacker can locate and access uploaded files. Access to those files may facilitate further attacks.