CNNVD-202510-336 Information

CNNVD ID

CNNVD-202510-336

CVE-2025-59737

  • CNNVD Published: 2025-10-02

Description (Chinese)

AndSoft e-TMS是西班牙AndSoft公司的一款物流管理软件。 AndSoft e-TMS 25.03版本存在命令注入漏洞,该漏洞源于对参数m的操作不当,可能导致操作系统命令注入攻击。

Description (English)

AndSoft e-TMS is a logistics management software for AndSoft in Spain. AndSoft e-TMS 25.03 has a command-injecting loophole, which results from inappropriate operation of parameter m, which may lead to an operational system command-injection attack.

Hazard Level

Low

Vulnerability Type

命令注入

Affected Vendor

AndSoft

Published

2025-10-02

Last Modified

2026-02-24

References

https://www.incibe.es/en/incibe-cert/notices/aviso/update-24092025-multiple-vulnerabilities-andsofts-e-tms

Patch

https://andsoft.es/es/solucio-1/menu-1/caracteristicas.html

Share on: