πŸ” CVE Alert

CVE-2025-14602

UNKNOWN 0.0

Weak File Name Generation in vsDesk

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to accurately guess or brute-force the generated filename within a short time window.Β An attacker can successfully locate and access uploaded files, which can be used to facilitate further attacks. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.

CWE CWE-340 CWE-377
Vendor vsdesk
Product vsdesk
Published Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for vsdesk vsdesk

Be the first to know when new unknown vulnerabilities affecting vsdesk vsdesk are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

Affected Versions

vsDesk / vsDesk
11.06.02

References

NVD β†— CVE.org β†— EPSS Data β†—
github.com: https://github.com/klsecservices/Advisories/blob/master/KLSA-00294-Weak-File-Name-Generation-in-vsDesk.md

Credits

The vulnerability was discovered by Kirill Nikolaev from Kaspersky (https://kaspersky.com)