CVE-2025-34179 Details
Description
NetSupport Manager < 14.12.0001 contains an unauthenticated SQL injection vulnerability in its Connectivity Server/Gateway HTTPS request handling. The server evaluates request URIs using an unsanitized SQLite query against the FileLinks table in gateway.db. By injecting SQL through the LinkName/URI value, a remote attacker can control the FileName field used by the server to read and return files from disk, resulting in arbitrary local file disclosure.
A SQL injection vulnerability has been identified in NetSupport Manager versions prior to 14.12.0001. This vulnerability exists in the Connectivity Server/Gateway component, which handles HTTPS requests. The issue arises because the server processes request URIs using an unsanitized SQLite query against the FileLinks table in gateway.db. By injecting SQL through the LinkName/URI value, a remote attacker can manipulate the FileName field to read and return files from the disk, leading to unauthorized local file disclosure.
NetSupport has released a patch for this vulnerability in version 14.12.0001. Users are advised to update their NetSupport Manager Gateways, Controls, and Clients to this version. For those running Gateway Servers on version 12.70 to 12.80 or 14.00 to 14.10, an update is available to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 15, 2025CISA-ADP
Assessed Dec 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.netsupportsoftware.com/knowledge-base/updating-and-securing-netsupport-manager/ | [email protected] | AdvisoryRemedyVendor |
| https://ret2.me/post/2025-12-04-exploiting-netsupport-gateway/ | [email protected] | BundleExploitTechnical Analysis |
| https://www.vulncheck.com/advisories/netsupport-manager-unauthenticated-sqli-local-file-disclosure | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| NetSupport Manager | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 15, 2025 | CVE Modified | [email protected] |
| Dec 15, 2025 | New CVE Received | [email protected] |
Volerion