CVE-2025-14520 describes a critical path traversal vulnerability in baowzh hfly, affecting versions up to 638ff9abe9078bc977c132b37acbe1900b63491c. This flaw, located in the /admin/index.php/datafile/delfile function, allows remote attackers to manipulate the 'filename' argument, potentially leading to unauthorized file deletion or modification. With a CVSS score of 9.1 (CRITICAL), the vulnerability is easily exploitable over the network without user interaction, resulting in high impact to data integrity and availability. While public exploit code is available, there is currently no evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2016-05-11CPE matchmatch criteria | cpe:2.3:a:baowzh:hfly:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.