7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Description
TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could use these APIs through phishing. Additionally, one of the APIs contains an Absolute Path Traversal vulnerability, allowing attackers to delete arbitrary files on the user's system.
Basic Information
ID
CVE-2025-13282
Source
twcert
Published
Nov 17, 2025 at 03:24
Affected Product
Vendor
Chunghwa Telecom
Product
TenderDocTransfer
Affected Versions
Chunghwa Telecom TenderDocTransfer 0