First published: Tue May 06 2025(Updated: )
Unrestricted file upload in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to upload any file within the server, even a malicious file to obtain a Remote Code Execution (RCE).
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
TCMAN GIM |
The vulnerability has been fixed by the TCMAN team in version 1280.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-40625 is high due to its potential for Remote Code Execution.
To fix CVE-2025-40625, ensure that file upload functionalities are properly validated and restricted.
CVE-2025-40625 affects TCMAN's GIM version 11.
CVE-2025-40625 can be exploited by unauthenticated attackers.
An attacker can upload malicious files, potentially leading to Remote Code Execution.