CyberRota Analysis
AI-GeneratedThe TEN Framework version 0.11.71 is vulnerable to unauthenticated arbitrary file read and write vulnerabilities in its TMAN Designer API endpoints, allowing attackers to exploit these weaknesses via POST and PUT requests. This could lead to unauthorized access to sensitive files or the injection of malicious content, potentially enabling code execution on the affected systems. Organizations using this framework should prioritize patching or mitigating this vulnerability to protect against severe security breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT requests to the /api/designer/v1/file-content endpoints to read arbitrary files or write malicious content to system paths, enabling code execution through authorized_keys, cron files, or executable graph files.