QOCA aim AI Medical Cloud Platform developed by Quanta Computer has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
References
| Link | Resource |
|---|---|
| https://www.twcert.org.tw/en/cp-139-10616-cd942-2.html | Third Party Advisory |
| https://www.twcert.org.tw/tw/cp-132-10615-157a3-1.html | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-01-05 09:15
Updated : 2026-01-20 21:10
NVD link : CVE-2025-15240
Mitre link : CVE-2025-15240
CVE.ORG link : CVE-2025-15240
JSON object : View
Products Affected
quantatw
- qoca_aim
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
