Andsoft's vulnerability footprint concentrates in a narrowly scoped transportation-management platform, E-TMS, that despite modest product breadth carries notable exposure due to its critical role in logistics operations. The vendor's disclosures skew strongly toward serious outcomes, with a substantial share reaching critical severity, reflecting the platform's direct handling of user input across web interfaces and system commands. Vulnerabilities recur across a consistent cluster of input-handling and injection weakness classes—cross-site scripting, command injection, OS command injection, SQL injection, and path traversal—that are characteristic of web-facing applications with insufficient sanitization boundaries. Defenders operating E-TMS should prioritize patching releases from this vendor and apply strict input validation and access controls at the application tier; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Andsoft over time
Signals from CVEs in this vendor scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-59743CRITICAL SQL injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability could allow an attacker to retrieve, create, update, and delete databases by sending a POST request. The r | Oct 2, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-59739CRITICAL Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a PO | Oct 2, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-59735CRITICAL Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a PO | Oct 2, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-59742CRITICAL SQL injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability could allow an attacker to retrieve, create, update, and delete databases by sending a POST request. The r | Oct 2, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-59740CRITICAL Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a PO | Oct 2, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-59738CRITICAL Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a PO | Oct 2, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-59737CRITICAL Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a PO | Oct 2, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-59736CRITICAL Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a PO | Oct 2, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-59741CRITICAL Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a PO | Oct 2, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-59744HIGH Path traversal vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to access files only within the web root using the “docurl” parameter in “/lib/asp/DOC | Oct 2, 2025 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (40 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Andsoft.
Media articles that mention a CVE ID that affects a product developed by Andsoft — matched by CVE ID, not by vendor name.