Weak File Name Generation in vsDesk Application
CVE-2025-14602

5.3MEDIUM

Key Information:

Vendor

Vsdesk

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2025-14602?

The vsDesk application exhibits a vulnerability in its file name generation process, which relies on a weak and predictable mechanism based on request timestamps. This flaw enables remote attackers to guess or brute-force the generated filenames within a minimal timeframe. Successful exploitation allows unauthorized access to uploaded files, facilitating potential follow-up attacks. It is crucial for users of affected versions to apply the available patch to mitigate this risk.

Affected Version(s)

vsDesk 11.06.02

vsDesk 14.0101

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The vulnerability was discovered by Kirill Nikolaev from Kaspersky (https://kaspersky.com)
.