← CVE Tracker
9.8CRITICAL

CVE-2025-59741 — Operating system command injection vulnerability in AndSoft's e-TMS v25.03.

Andsoft · E-Tms · Published 2 Oct 2025 · Modified 1 Oct 2026

Description

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned identifier is a 'm' parameter in '/CLT/LOGINERRORFRM.ASP'.

References

What to do
  1. Check whether E-Tms is in your asset inventory.
  2. Patch in the next maintenance window; prioritise internet-facing systems.
  3. Record the decision in your risk register for audit evidence.
Alert me on similar CVEs →
Share

Link: adminadda.com/cve/CVE-2025-59741