CVE-2025-10267

Publication date

2025-09-12 10:24:06

Family

twcert

State

PUBLISHED

Description

NUP Portal developed by NewType Infortech has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly upload files. If the attacker manages to bypass the file extension restrictions, they could upload a webshell and execute it on the server side.