Home

Description

zdh_web is a data collection, processing, monitoring, scheduling, and management platform. In zdh_web thru 5.6.17, insufficient validation of file upload paths in the application allows an authenticated user to write arbitrary files to the server file system, potentially overwriting existing files and leading to privilege escalation or remote code execution.

PUBLISHED Reserved 2025-11-18 | Published 2025-12-05 | Updated 2025-12-05 | Assigner mitre

References

github.com/zhaoyachao/zdh_web

github.com/zhaoyachao/zdh_web/pull/39

github.com/...ommit/b2423378a8bf83f159f19ce4e14eac71c939793a

github.com/zhaoyachao/zdh_web/issues/40

cve.org (CVE-2025-65897)

nvd.nist.gov (CVE-2025-65897)