CVE-2025-2819 Details
Description
There is a risk of unauthorized file uploads in GT-SoftControl and potential file overwrites due to insufficient validation in the file selection process. This could lead to data integrity issues and unauthorized access by an authenticated privileged user.
A vulnerability exists in Bizerba GT-SoftControl versions prior to 6.0, allowing unauthorized file uploads and potential file overwrites. This issue arises from inadequate validation in the file selection process, which could result in data integrity problems and unauthorized access for authenticated privileged users.
Users are advised to update GT-SoftControl to the latest version. Additionally, prevent unauthorized physical access to the device and disable E-Service to avoid remote access.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 26, 2025CISA-ADP
Assessed Mar 26, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.bizerba.com/downloads/global/information-security/2025/bizerba-sa-2025-0001.pdf | bizerba | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | bizerba |
Affected Products
| Product | Versions |
|---|---|
| Bizerba GT-SoftControl | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | bizerba |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 26, 2025 | New CVE Received | bizerba |
Volerion