CVE-2025-2155

HIGH

Echo Call Center Services Trade and Industry Inc. Specto CM <170320...

Title source: llm
STIX 2.1

Description

Unrestricted Upload of File with Dangerous Type vulnerability in Echo Call Center Services Trade and Industry Inc. Specto CM allows Remote Code Inclusion. This issue affects Specto CM: before 17032025.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource government-resource broken-link
https://www.usom.gov.tr/bildirim/tr-25-0480

Scores

CVSS v3 8.8
EPSS 0.0029
EPSS Percentile 20.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
Echo Call Center Services Trade and Industry Inc./Specto CM < 17032025
Published Dec 24, 2025
Tracked Since Feb 18, 2026