2025-12-24 14:31CVE-2025-2155TR-CERT
PUBLISHED5.2CWE-434

Arbitrary File Upload in EchoCCS's Specto CM

Unrestricted Upload of File with Dangerous Type vulnerability in Echo Call Center Services Trade and Industry Inc. Specto CM allows Remote Code Inclusion.This issue affects Specto CM: before 17032025.

Problem type

Affected products

Echo Call Center Services Trade and Industry Inc.

Specto CM

< 17032025 - AFFECTED

References

GitHub Security Advisories

GHSA-pgph-4c45-hj8g

Unrestricted Upload of File with Dangerous Type vulnerability in Echo Call Center Services Trade...

https://github.com/advisories/GHSA-pgph-4c45-hj8g

Unrestricted Upload of File with Dangerous Type vulnerability in Echo Call Center Services Trade and Industry Inc. Specto CM allows Remote Code Inclusion.This issue affects Specto CM: before 17032025.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2025-2155
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2025-2155",
    "assignerOrgId": "ca940d4e-fea4-4aa2-9a58-591a58b1ce21",
    "assignerShortName": "TR-CERT",
    "dateUpdated": "2025-12-24T16:22:27.231Z",
    "dateReserved": "2025-03-10T11:45:13.203Z",
    "datePublished": "2025-12-24T14:31:07.708Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "ca940d4e-fea4-4aa2-9a58-591a58b1ce21",
        "shortName": "TR-CERT",
        "dateUpdated": "2025-12-24T14:31:07.708Z"
      },
      "datePublic": "2025-12-24T14:29:00.000Z",
      "title": "Arbitrary File Upload in EchoCCS's Specto CM",
      "descriptions": [
        {
          "lang": "en",
          "value": "Unrestricted Upload of File with Dangerous Type vulnerability in Echo Call Center Services Trade and Industry Inc. Specto CM allows Remote Code Inclusion.This issue affects Specto CM: before 17032025.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "Unrestricted Upload of File with Dangerous Type vulnerability in Echo Call Center Services Trade and Industry Inc. Specto CM allows Remote Code Inclusion.<p>This issue affects Specto CM: before 17032025.</p>"
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "Echo Call Center Services Trade and Industry Inc.",
          "product": "Specto CM",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "17032025"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-434 Unrestricted Upload of File with Dangerous Type",
              "cweId": "CWE-434",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://www.usom.gov.tr/bildirim/tr-25-0480"
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-253",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-253 Remote Code Inclusion"
            }
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ],
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH"
          }
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Saadet Elif TOKUOĞLU",
          "type": "finder"
        },
        {
          "lang": "en",
          "value": "Berk İMRAN",
          "type": "finder"
        }
      ]
    },
    "adp": [
      {
        "providerMetadata": {
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP",
          "dateUpdated": "2025-12-24T16:22:27.231Z"
        },
        "title": "CISA ADP Vulnrichment",
        "metrics": [
          {}
        ]
      }
    ]
  }
}