Description
The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to accurately guess or brute-force the generated filename within a short time window. An attacker can successfully locate and access uploaded files, which can be used to facilitate further attacks.
Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.
Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 20 Aug 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vsdesk
Vsdesk vsdesk |
|
| Vendors & Products |
Vsdesk
Vsdesk vsdesk |
Thu, 20 Aug 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to accurately guess or brute-force the generated filename within a short time window. An attacker can successfully locate and access uploaded files, which can be used to facilitate further attacks. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch. | |
| Title | Weak File Name Generation in vsDesk | |
| Weaknesses | CWE-340 CWE-377 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Kaspersky
Published:
Updated: 2026-08-20T15:18:39.898Z
Reserved: 2025-12-12T18:42:14.784Z
Link: CVE-2025-14602
No data.
Status : Received
Published: 2026-08-20T07:16:30.623
Modified: 2026-08-20T07:16:30.623
Link: CVE-2025-14602
No data.
OpenCVE Enrichment
Updated: 2026-08-20T09:07:23Z