🔐 CVE Alert

CVE-2025-34181

UNKNOWN 0.0

NetSupport Manager < 14.12.0001 Authenticated Path Traversal Arbitrary File Write RCE

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

NetSupport Manager < 14.12.0001 contains an arbitrary file write vulnerability in its Connectivity Server/Gateway PUTFILE request handler. An attacker with a valid Gateway Key can supply a crafted filename containing directory traversal sequences to write files to arbitrary locations on the server. This can be leveraged to place attacker-controlled DLLs or executables in privileged paths and achieve remote code execution in the context of the NetSupport Manager connectivity service.

CWE CWE-22
Vendor netsupport software
Product manager
Published Dec 15, 2025
Last Updated May 14, 2026
Stay Ahead of the Next One

Get instant alerts for netsupport software manager

Be the first to know when new unknown vulnerabilities affecting netsupport software manager are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

NetSupport Software / Manager
0 < 14.12.0001

References

NVD ↗ CVE.org ↗ EPSS Data ↗
kb.netsupportsoftware.com: https://kb.netsupportsoftware.com/knowledge-base/updating-and-securing-netsupport-manager/ vulncheck.com: https://www.vulncheck.com/advisories/netsupport-manager-authenticated-path-traversal-arbitrary-write-rce ret2.me: https://ret2.me/post/2025-12-04-exploiting-netsupport-gateway/

Credits

Chris Leech