CVE-2025-7917

HIGH

WinMatrix3 Web - RCE

Title source: llm
STIX 2.1

Description

WinMatrix3 Web package developed by Simopro Technology has an Arbitrary File Upload vulnerability, allowing remote attackers with administrator privileges to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

References (2)

Core 2
Core References
Various Sources third-party-advisory
https://www.twcert.org.tw/tw/cp-132-10258-16bbf-1.html
Various Sources third-party-advisory
https://www.twcert.org.tw/en/cp-139-10263-5f2e7-2.html

Scores

CVSS v3 7.2
EPSS 0.0045
EPSS Percentile 63.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
Simopro Technology/WinMatrix3 Web package < 1.2.39.5
Published Jul 21, 2025
Tracked Since Feb 18, 2026