A vulnerability was found in Yottamaster DM2, DM3 and DM200 up to 1.2.23/1.9.12. Affected by this issue is some unknown functionality of the component File Upload. Performing manipulation results in path traversal. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
History

Tue, 09 Dec 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Yottamaster
Yottamaster dm2
Yottamaster dm200
Yottamaster dm3
Vendors & Products Yottamaster
Yottamaster dm2
Yottamaster dm200
Yottamaster dm3

Mon, 08 Dec 2025 14:15:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 08 Dec 2025 08:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Yottamaster DM2, DM3 and DM200 up to 1.2.23/1.9.12. Affected by this issue is some unknown functionality of the component File Upload. Performing manipulation results in path traversal. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Yottamaster DM2/DM3/DM200 File Upload path traversal
Weaknesses CWE-22
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-12-08T08:32:06.058Z

Updated: 2025-12-08T14:03:14.943Z

Reserved: 2025-12-07T15:35:49.584Z

Link: CVE-2025-14224

cve-icon Vulnrichment

Updated: 2025-12-08T14:02:49.376Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-08T09:15:46.273

Modified: 2025-12-08T18:26:19.900

Link: CVE-2025-14224

cve-icon Redhat

No data.