« Volver al listado

CVE-2025-14014

Estado: AplazadaCrítica (9.8)—

Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software Hardware Industry and Trade Ltd. Co. Smart Panel allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects Smart Panel: before 20251215.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

CWE-434 (unrestricted file upload) en aplicación web expuesta (AV:N, PR:N). Permite subir shell web y acceder a funcionalidad sin restricción ACL.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-14014",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-14014",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-02-12T14:42:31.555160Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "iletisim@usom.gov.tr",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "iletisim@usom.gov.tr",
      "affectedData": [
        {
          "vendor": "NTN Information Processing Services Computer Software Hardware Industry and Trade Ltd. Co.",
          "product": "Smart Panel",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "20251215",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-02-12T15:16:02.657",
  "references": [
    {
      "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0064",
      "source": "iletisim@usom.gov.tr"
    },
    {
      "url": "https://www.usom.gov.tr/bildirim/tr-26-0064",
      "source": "iletisim@usom.gov.tr"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "iletisim@usom.gov.tr",
      "description": [
        {
          "lang": "en",
          "value": "CWE-434"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software Hardware Industry and Trade Ltd. Co. Smart Panel allows Accessing Functionality Not Properly Constrained by ACLs.\n\nThis issue affects Smart Panel: before 20251215."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de carga sin restricciones de archivo con tipo peligroso en NTN Information Processing Services Computer Software Hardware Industry and Trade Ltd. Co. Smart Panel permite acceder a funcionalidad no restringida adecuadamente por ACLs. Este problema afecta a Smart Panel: antes del 20251215."
    }
  ],
  "lastModified": "2026-06-17T08:35:10.357",
  "sourceIdentifier": "iletisim@usom.gov.tr"
}