Missing Authentication Vulnerability in NUP Portal by NewType Infortech
CVE-2025-10267

6.9MEDIUM

Key Information:

Vendor
CVE Published:
12 September 2025

What is CVE-2025-10267?

The NUP Portal, created by NewType Infortech, is vulnerable to a missing authentication issue that can be exploited by unauthenticated remote attackers. This flaw allows malicious actors to upload files directly to the server without proper verification. If the attackers manage to circumvent the file extension restrictions set in place, they can upload a webshell, granting them the capability to execute arbitrary commands on the server. This significant security concern highlights the necessity for robust authentication mechanisms to prevent unauthorized access and safeguard server integrity.

Affected Version(s)

NUP Portal 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-10267 : Missing Authentication Vulnerability in NUP Portal by NewType Infortech