Unrated severityNVD Advisory· Published Jul 8, 2025· Updated Jul 8, 2025
CVE-2025-40738
CVE-2025-40738
Description
A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly validate file paths when extracting uploaded ZIP files. This could allow an attacker to write arbitrary files to restricted locations and potentially execute code with elevated privileges (ZDI-CAN-26572).
Affected products
2- Range: < V4.0
- Siemens/SINEC NMSv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.