CVE-2025-10468

7.5

Beyaz Computer · CityPlus

A path traversal vulnerability in Beyaz Computer CityPlus allows unauthenticated attackers to access restricted files on the host system.

Executive summary

A critical path traversal vulnerability in Beyaz Computer CityPlus allows unauthenticated remote attackers to gain unauthorized access to sensitive files on the host system.

Vulnerability

The application fails to properly sanitize user-supplied input used in file path operations, which permits an unauthenticated attacker to bypass directory restrictions and read arbitrary files from the server.

Business impact

Successful exploitation of this vulnerability can lead to the exposure of sensitive configuration files, credentials, or system data, resulting in significant unauthorized information disclosure. With a CVSS score of 7.5, the vulnerability is classified as High severity, reflecting the ease of remote, unauthenticated exploitation and the potential for severe impact on confidentiality.

Remediation

Immediate Action: Administrators should verify if a security update is available from Beyaz Computer and apply it immediately to move to version 24.29375 or higher.

Proactive Monitoring: Security teams should review web access logs for patterns indicative of path traversal attempts, such as sequences like ../, and monitor for unusual file access requests targeting sensitive system directories.

Compensating Controls: Deploy a Web Application Firewall (WAF) configured with rules to detect and block directory traversal attack patterns to mitigate risk while awaiting vendor patches.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the potential for unauthorized data access, this vulnerability presents a significant risk to organizational confidentiality. Administrators must prioritize the identification of all instances of CityPlus within their environment and apply the necessary updates as soon as the vendor provides a formal patch.

More Beyaz Computer CVEs

Sources

Originally found and disclosed by Abdullah Beyhan, per the CVE Program record.