Vulnerability in Verysync微力同步 Web Administration Module Allows Unrestricted File Upload
CVE-2025-14199
Key Information:
Badges
What is CVE-2025-14199?
An identified flaw in the Web Administration Module of Verysync 微力同步 versions up to 2.21.3 allows an attacker to perform unrestricted file uploads through a specific API endpoint. This vulnerability can be remotely exploited, potentially resulting in unauthorized access and manipulation of sensitive data. Despite the vendor being informed about the vulnerability, there has been no response or remediation. Users are strongly advised to evaluate their security posture and take preventive measures.
Affected Version(s)
微力同步 2.21.0
微力同步 2.21.1
微力同步 2.21.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
