CNNVD-202601-3813 Information

CNNVD ID

CNNVD-202601-3813

CVE-2025-69612

  • CNNVD Published: 2026-01-22

Description (Chinese)

TMS Management Console是美国TMS公司的一个管理控制台软件。 TMS Management Console 6.3.7.27386.20250818版本存在安全漏洞,该漏洞源于profile dashboard中的Download Template功能未处理filePath参数中的目录遍历序列,可能导致经过身份验证的用户读取任意文件。

Description (English)

TMS Management Console is a management console software for TMS. There is a security loophole in version 6.3.7.27386.20250818, which stems from the fact that the Download Template function in the protocol dashboard does not handle the directory-by-line sequences in the filePath parameter, which may lead to any access to any file by an identified user.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

TMS

Published

2026-01-22

Last Modified

2026-02-24

References

http://tms.com https://github.com/Cr0wld3r/CVE-2025-69612/blob/main/PoC.md https://tmsglobalsoft.com/ https://access.redhat.com/security/cve/cve-2025-69612

Share on: