Impact
The vulnerability allows manipulation of the File argument on the /dm/dispatch/userinfo/upload endpoint, resulting in unrestricted upload of arbitrary files to the server. The upload function is exposed remotely, so an attacker can deliver files without authenticating.
Affected Systems
Rongzhitong’s Visual Integrated Command and Dispatch Platform up to 20260617 is vulnerable; newer releases may contain a fix but are not listed in the data.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate‑to‑high risk. Because the upload functionality is exposed remotely, the exploit can be performed from outside the network. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, yet publicly available exploits demonstrate a realistic attack window, especially given the lack of authentication or file‑type restrictions.
OpenCVE Enrichment