SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2025-14602

MEDIUM · CVSS 5.3 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability arises from the application's weak and predictable method of generating uploaded file names based on request timestamps, allowing remote attackers to guess or brute-force these filenames. This could lead to unauthorized access to sensitive files, potentially facilitating further attacks. Organizations using affected versions should prioritize applying the vendor's patch, particularly those running versions prior to 14.0101.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-14602
Severity
MEDIUM
CVSS
5.3
EPSS
0.27%

Original NVD Description

The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to accurately guess or brute-force the generated filename within a short time window. An attacker can successfully locate and access uploaded files, which can be used to facilitate further attacks. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.