CVE-2025-11908 is an unrestricted file upload vulnerability in Shenzhen Ruiming Technology Streamax Crocus version 1.3.40, specifically within the uploadFile function of the /FileDir.do?Action=Upload endpoint. This flaw allows an authenticated attacker to remotely upload arbitrary files, leading to high impacts on confidentiality, integrity, and availability, as reflected by its CVSS score of 8.8 (High). While a public exploit has been released, there is no evidence of active exploitation in the wild, nor significant community discussion or media coverage. The vendor has not responded to disclosure attempts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3.40CPE matchmatch criteria | cpe:2.3:a:streamax:streamax_crocus:1.3.40:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.