CVE-2025-2702

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Mar 24, 2025
CWE ID 434
CWE ID 284

Summary

CVE-2025-2702 is a critical vulnerability affecting Softwin WMX3 3.1. The issue lies within the ImageAdd function of the /ImageAdd.ashx file. An attacker can exploit this flaw by manipulating the argument File, enabling unrestricted file uploads. This vulnerability can be exploited remotely, meaning an attacker does not need to have local access to the system. The exploit for this vulnerability has been made public, increasing the risk of potential attacks. Despite early notification, the vendor has not responded to the disclosure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share