Arbitrary File Copy and Path Traversal in TenderDocTransfer by Chunghwa Telecom
CVE-2025-13283
What is CVE-2025-13283?
TenderDocTransfer, a product developed by Chunghwa Telecom, is susceptible to an Arbitrary File Copy and Path Traversal vulnerability. The application operates a local web server and offers APIs for interaction with target websites. However, these APIs lack adequate CSRF protection, allowing unauthenticated remote attackers to exploit them, potentially through phishing schemes. Additionally, the API's Absolute Path Traversal flaw enables attackers to copy arbitrary files from the user's system to any desired location, which can lead to information leakage or excessive hard drive consumption due to large file transfers.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
TenderDocTransfer 0 < 0.41.159
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
