CVE-2025-13282 Details
Description
TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could use these APIs through phishing. Additionally, one of the APIs contains an Absolute Path Traversal vulnerability, allowing attackers to delete arbitrary files on the user's system.
An arbitrary file deletion vulnerability has been identified in TenderDocTransfer, a file transfer application developed by Chunghwa Telecom, prior to version 0.41.159. The vulnerability arises from the application's local web server, which exposes APIs for communication with target websites. These APIs lack Cross-Site Request Forgery (CSRF) protection, allowing unauthenticated remote attackers to exploit them, potentially through phishing. One of the APIs is vulnerable to absolute path traversal, enabling attackers to delete arbitrary files from the user's system.
Users are advised to update TenderDocTransfer to version 0.41.159 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 17, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.twcert.org.tw/en/cp-139-10511-10f3a-2.html | [email protected] | Third Party Advisory |
| https://www.twcert.org.tw/tw/cp-132-10510-3719c-1.html | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
| CWE-36 | Absolute Path Traversal | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cht tenderdoctransfer | < 0.41.159 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 19, 2025 | Initial Analysis | [email protected] |
| Nov 17, 2025 | New CVE Received | [email protected] |