Arbitrary File Deletion Issue in TenderDocTransfer by Chunghwa Telecom
CVE-2025-13282
What is CVE-2025-13282?
The TenderDocTransfer application developed by Chunghwa Telecom has a critical security flaw involving Arbitrary File Deletion. The application features a local web server that enables APIs for interaction with remote websites. However, it is exposed to risks due to the absence of Cross-Site Request Forgery (CSRF) protection, facilitating unauthorized access through phishing attacks. Additionally, an Absolute Path Traversal vulnerability in one of the APIs allows attackers to delete any file on the user's system, significantly compromising user data and security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
TenderDocTransfer 0 < 0.41.159
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
