Vulnerability Details CVE-2025-40738
A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly validate file paths when extracting uploaded ZIP files. This could allow an attacker to write arbitrary files to restricted locations and potentially execute code with elevated privileges (ZDI-CAN-26572).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 30.8%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2025-40738
-
cpe:2.3:a:siemens:sinec_nms:1.0
-
cpe:2.3:a:siemens:sinec_nms:1.0.3
-
cpe:2.3:a:siemens:sinec_nms:2.0
-
cpe:2.3:a:siemens:sinec_nms:3.0