CVE-2025-5952 Details
Description
A vulnerability, which was classified as critical, has been found in Zend.To up to 6.10-6 Beta. This issue affects the function exec of the file NSSDropoff.php. The manipulation of the argument file_1 leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 6.10-7 is able to address this issue. It is recommended to upgrade the affected component. This affects a rather old version of the software. The vendor recommends updating to the latest release. Additional countermeasures have been added in 6.15-8.
A critical command injection vulnerability has been identified in Zend.To versions prior to 6.10-7 Beta. The issue arises in the NSSDropoff.php file, where the exec function is called with unsanitized file names from user uploads. This vulnerability allows unauthenticated attackers to execute arbitrary system commands during the file upload process. The vulnerability can be exploited remotely.
Users are advised to upgrade to Zend.To version 6.10-7 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 10, 2025CISA-ADP
Assessed Jun 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://matheuscezar.github.io/2025/05/24/0-day-in-zend-to.html | [email protected] | ExploitTechnical Description |
| https://vuldb.com/?ctiid.311789 | [email protected] | AdvisoryExploit |
| https://vuldb.com/?id.311789 | [email protected] | AdvisoryExploitRemedy |
| https://vuldb.com/?submit.589178 | [email protected] | AdvisoryTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Zend.To | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Jun 10, 2025 | CVE Modified | [email protected] |
| Jun 10, 2025 | New CVE Received | [email protected] |
Volerion