CVE-2025-59793
CRIT 9.9Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to upload files. However, the application doesn't properly sanitize the jobDirectory parameter, which allows path traversal sequences to be included. This allows writing files to arbitrary local filesystem locations and may subsequently lead to remote code execution.
Affected Applications in Environment
6
Rufus
v4.11.2285
5 devices
Rufus
v4.9.2256
1 device
Rufus
v4.13.2316
8 devices
Rufus
v4.5.2180
1 device
Rufus
v4.7.2231
1 device
Rufus
v4.6.2208
2 devices
Affected Devices
13
BRAXTONCOMPUTER
Windows
DESKTOP-1OVQ2S7
Windows
DPCUBC-9MYYYQ2
Windows
DPEECE-WILBUR
Windows
DPINFT-02609239
Windows
DPINFT-24679149
Windows
DPINFT-983F2T2
Windows
DPINFT-D145JJ7D
Windows
DPINFT-L1182PBW
Windows
FACWADE5680
Windows
LIBGHOST
Windows
NCH-194817
Windows
SILK
Windows