Impact
A path traversal flaw in Tencent Mass Service Engine in Cluster (MSEC) permits an attacker who can send a crafted POST request to reference directories outside the intended file system using ".../". The vulnerability is classified as CWE-22 and allows unauthenticated remote code execution as the root user once a malicious webshell is uploaded.
Affected Systems
The affected product is Tencent Mass Service Engine in Cluster (MSEC). No specific version range was provided, so any deployment of this product is potentially impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 9.3 categorizes this vulnerability as critical. The EPSS rating of less than 1% indicates that, at this time, the likelihood of exploitation is low. The flaw is not listed in CISA’s KEV catalog. Remote exploitation requires sending a crafted POST request to the file‑upload endpoint that interprets directory traversal sequences such as "../" to gain access to arbitrary filesystem locations. Once an attacker uploads a webshell through this vector, the code executes with root privileges, allowing full system compromise.
OpenCVE Enrichment