AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-13282

HIGH · CVSS 8.1 EPSS 0.26%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-11-17 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.1. It may be remotely exploitable.

CVE
CVE-2025-13282
Severity
HIGH
CVSS
8.1
EPSS
0.26%

Original NVD Description

TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could use these APIs through phishing. Additionally, one of the APIs contains an Absolute Path Traversal vulnerability, allowing attackers to delete arbitrary files on the user's system.

Related CVEs

Other vulnerabilities affecting the same vendor(s)