CVE-2025-14014 PUBLISHED

Insecure File Upload in NTN Informatics' Smart Panel

Assigner: TR-CERT
Reserved: 04.12.2025 Published: 12.02.2026 Updated: 12.02.2026

Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software Hardware Industry and Trade Ltd. Co. Smart Panel allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Smart Panel: before 20251215.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor NTN Information Processing Services Computer Software Hardware Industry and Trade Ltd. Co.
Product Smart Panel
Versions Default: unaffected
  • affected from 0 to 20251215 (excl.)

Credits

  • Anonim finder

References

Problem Types

  • CWE-434 Unrestricted Upload of File with Dangerous Type CWE

Impacts

  • CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs