CVE-2025-59740 PUBLISHED

Multiple vulnerabilities in AndSoft's e-TMS

Assigner: INCIBE
Reserved: 19.09.2025 Published: 02.10.2025 Updated: 02.10.2025

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned identifier is a 'm' parameter in '/clt/LOGINFRM_CAT.ASP'.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor AndSoft
Product e-TMS
Versions Default: unaffected
  • Version v25.03 version is affected

Solutions

The vulnerability has been resolved in patches e-TMS VNL 25001 and VNL 25010.

Credits

  • Maximilian Hildebrand (m10x.de) finder

References

Problem Types

  • CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection') CWE