CVE-2025-67260
The Terrapack software, from ASTER TEC / ASTER S.p.A., with the indicated components and versions has a file upload vulnerability that may allow attackers to execute arbitrary code.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.38%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Terrapack software, from ASTER TEC / ASTER S.p.A., with the indicated components and versions has a file upload vulnerability that may allow attackers to execute arbitrary code. Vulnerable components include Terrapack TkWebCoreNG:: 1.0.20200914, Terrapack TKServerCGI 2.5.4.150, and Terrapack TpkWebGIS Client 1.0.0.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.38% probability · 32th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- aster-te/terrapack tkservercgi · aster-te/terrapack tkwebcoreng · aster-te/terrapack tpkwebgis
- Source
- cve@mitre.org
References
- https://github.com/edi-marc/Vulnerability_List/tree/main/CVE_TerrapackThird Party Advisory
- https://packetstorm.news/files/id/217271Not Applicable
- https://www.acn.gov.it/portale/en/csirt-italiaBroken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.