216.73.217.22

CVE-2025-40625

· Published 06/05/2025 11:15 · Modified 06/05/2025 11:15

Labels: CVE-2025-40625 2025-05-06CVE-2025-40625CWE-89[email protected]

Essential information

Published
06/05/2025 11:15
Modified
06/05/2025 11:15
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Unrestricted file upload in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to upload any file within the server, even a malicious file to obtain a Remote Code Execution (RCE).

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
tcan / gam cpe:2.3:a:tcan:gam:11:*:*:*:*:*:*:*

References