High severity8.1NVD Advisory· Published Dec 18, 2025· Updated Apr 14, 2026
CVE-2025-40898
CVE-2025-40898
Description
A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validation of the input file. An authenticated user with limited privileges, by uploading a specifically-crafted Arc data archive, can potentially write arbitrary files in arbitrary paths, altering the device configuration and/or affecting its availability.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- security.nozominetworks.com/NN-2025:15-01nvdMitigationVendor Advisory
- cert-portal.siemens.com/productcert/html/ssa-827968.htmlnvd
News mentions
0No linked articles in our index yet.