Security Advisory

CVE-2025-10267

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-09-12 10:24:06
Last updated 2025-09-12 15:17:33
Assigner twcert
CVSS score 6.9
State PUBLISHED

Description

NUP Portal developed by NewType Infortech has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly upload files. If the attacker manages to bypass the file extension restrictions, they could upload a webshell and execute it on the server side.