Unrestricted file upload in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to upload any file within the server, even a malicious file to obtain a Remote Code Execution (RCE).
Fixes

Solution

The vulnerability has been fixed by the TCMAN team in version 1280.


Workaround

No workaround given by the vendor.

History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00254}

epss

{'score': 0.00265}


Tue, 13 May 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Tcman
Tcman gim
CPEs cpe:2.3:a:tcman:gim:11.0:*:*:*:*:*:*:*
Vendors & Products Tcman
Tcman gim
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 07 May 2025 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89

Wed, 07 May 2025 07:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-434

Tue, 06 May 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 May 2025 11:00:00 +0000

Type Values Removed Values Added
Description Unrestricted file upload in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to upload any file within the server, even a malicious file to obtain a Remote Code Execution (RCE).
Title Multiple vulnerabilities in TCMAN's GIM
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-05-07T06:41:41.523Z

Reserved: 2025-04-16T08:38:09.206Z

Link: CVE-2025-40625

cve-icon Vulnrichment

Updated: 2025-05-06T13:40:33.566Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-06T11:15:52.327

Modified: 2025-05-13T19:17:18.623

Link: CVE-2025-40625

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.