Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The vulnerability has been fixed by the TCMAN team in version 1280.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-13575 | Unrestricted file upload in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to upload any file within the server, even a malicious file to obtain a Remote Code Execution (RCE). |
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 13 May 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tcman
Tcman gim |
|
| CPEs | cpe:2.3:a:tcman:gim:11.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Tcman
Tcman gim |
|
| Metrics |
cvssV3_1
|
Wed, 07 May 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 |
Wed, 07 May 2025 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-434 |
Tue, 06 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 May 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unrestricted file upload in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to upload any file within the server, even a malicious file to obtain a Remote Code Execution (RCE). | |
| Title | Multiple vulnerabilities in TCMAN's GIM | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-05-07T06:41:41.523Z
Reserved: 2025-04-16T08:38:09.206Z
Link: CVE-2025-40625
Updated: 2025-05-06T13:40:33.566Z
Status : Analyzed
Published: 2025-05-06T11:15:52.327
Modified: 2025-05-13T19:17:18.623
Link: CVE-2025-40625
No data.
OpenCVE Enrichment
No data.
EUVD