Missing Authentication Vulnerability in NUP Portal by NewType Infortech
CVE-2025-10267
What is CVE-2025-10267?
The NUP Portal, created by NewType Infortech, is vulnerable to a missing authentication issue that can be exploited by unauthenticated remote attackers. This flaw allows malicious actors to upload files directly to the server without proper verification. If the attackers manage to circumvent the file extension restrictions set in place, they can upload a webshell, granting them the capability to execute arbitrary commands on the server. This significant security concern highlights the necessity for robust authentication mechanisms to prevent unauthorized access and safeguard server integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
NUP Portal 0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
