CVE-2025-34163
Dongsheng Logistics Software has a critical flaw that lets anyone upload any file type to a specific endpoint, enabling attackers to run code on the server. The vulnerability is present in versions before July 2025 and has been fixed in newer releases.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Dongsheng Logistics Software (all builds released before July 2025).
Real-world impact
An attacker can upload malicious scripts and execute them on the server, potentially taking full control of the system.
Why this severity
The CVSS score of 10 reflects that the flaw is exploitable over the network without authentication, allows arbitrary code execution, and has complete impact on confidentiality, integrity, and availability.
What to do about it
- 01Upgrade Dongsheng Logistics Software to a version released after July 2025.
NVD-referenced vendor advisory
Timeline
- Aug 27, 2025 · Aug 27, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 1d agoAdvisory updatedThe NVD record was last revised.
- Aug 5, 2026 · 19h agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.