Description
Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Software Repository Management allows Upload a Web Shell to a Web Server.

This issue affects Software Repository Management: before 2fb4acee.
Published: 2026-08-25
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An uncontrolled file upload flaw allows attackers to upload arbitrary files with dangerous content. The flaw is due to missing or insufficient validation of the file type and location. An attacker who can trigger the upload can drop a web shell or other executable code onto the server, giving them remote code execution on the web server. This could lead to full compromise, data exfiltration, or destruction of information stored by the system.

Affected Systems

Affected are installations of TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company's Software Repository Management module prior to the code commit 2fb4acee. The vulnerability exists in the repository’s upload endpoint used by authorized users for application binaries or documents. All users with write access to the repository are potentially at risk.

Risk and Exploitability

Severity is reflected in a CVSS score of 9.8, indicating critical risk. The EPSS score is not available, but given the high severity and the common nature of upload interfaces, the likelihood of exploitation should be treated as high. The vulnerability is not listed in the CISA KEV catalog; however, the likely attack vector is remote through the web application, requiring the attacker to either authenticate with an account that has upload rights or exploit a weakness that allows unauthenticated upload. Based on the description, it is inferred that the attacker could gain full control of the server by uploading a web shell.

Generated by OpenCVE AI on August 25, 2026 at 15:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the vendor’s patch that addresses the unrestricted upload flaw.
  • If the patch is unavailable, disable or tightly restrict the upload endpoint to allow only files of explicitly permitted types and set the upload directory permissions to non‑executable.
  • Enforce server‑side MIME type and file‑extension validation, and deploy a Web Application Firewall rule or rate limiter to block suspicious upload attempts.

Generated by OpenCVE AI on August 25, 2026 at 15:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Software Repository Management allows Upload a Web Shell to a Web Server. This issue affects Software Repository Management: before 2fb4acee.
Title File Upload in TRTEK Software's Software Repository Management
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-25T14:51:53.578Z

Reserved: 2026-07-20T11:44:04.532Z

Link: CVE-2026-16286

cve-icon Vulnrichment

Updated: 2026-08-25T14:46:07.909Z

cve-icon NVD

Status : Received

Published: 2026-08-25T15:16:30.180

Modified: 2026-08-25T15:16:30.180

Link: CVE-2026-16286

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T16:00:15Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type