Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-41723— Sauter: Directory Traversal in importFile SOAP Method

CVSS 9.8 · Critical EPSS 0.14% · P33
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-41723

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Sauter: Directory Traversal in importFile SOAP Method
Source: NVD (National Vulnerability Database)
Vulnerability Description
The importFile SOAP method is vulnerable to a directory traversal attack. An unauthenticated remote attacker bypass the path restriction and upload files to arbitrary locations.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
路径遍历:’…/…//’
Source: NVD (National Vulnerability Database)
Vulnerability Title
SAUTER多款产品 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
SAUTER EY-modulo 5 Building Automation Station是SAUTER公司的完整的楼宇管理解决方案。Sauter modu680-AS是瑞士Sauter公司的一个模块化自动化站兼web服务器。 SAUTER多款产品存在安全漏洞,该漏洞源于importFile SOAP方法容易受到目录遍历攻击,可能导致未经验证的远程攻击者绕过路径限制并上传文件到任意位置。以下产品受到影响:modulo 6 devices modu680-AS、modulo 6 devices modu6
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
Sautermodulo 6 devices modu680-AS 0.0.0 ~ Firmware v3.2.0 -
Sautermodulo 6 devices modu660-AS 0.0.0 ~ Firmware v3.2.0 -
Sautermodulo 6 devices modu612-LC 0.0.0 ~ Firmware v3.2.0 -
SauterEY-modulo 5 modu 5 modu524 0.0 ~ Firmware v6.0 -
SauterEY-modulo 5 modu 5 modu525 0.0 ~ Firmware v6.0 -
SauterEY-modulo 5 ecos 5 ecos504/505 0.0 ~ Firmware v6.0 -

II. Public POCs for CVE-2025-41723

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-41723

Please Login to view more intelligence information

Same Patch Batch · Sauter · 2025-10-22 · 6 CVEs total

CVE-2025-417198.8 HIGHSauter: Improper Validation of user-controlled data
CVE-2025-417247.5 HIGHSauter: Crash via Incomplete SOAP Request
CVE-2025-417227.5 HIGHSauter: Hard-coded Authentication Credentials
CVE-2025-417204.3 MEDIUMSauter: Arbitrary File Upload
CVE-2025-417212.7 LOWSauter: Command Injection

IV. Related Vulnerabilities

V. Comments for CVE-2025-41723

No comments yet


Leave a comment