ZeroHour

CVE-2025-34508

niche

Authenticated Path Traversal in ZendTo File Dropoff Functionality

CVSS 4.0
5.3 medium
EPSS
69%p99
Published
()
Modified
AI analysis

CVE-2025-34508 is a path traversal flaw (CWE-22) in the file dropoff functionality of ZendTo, a self-hosted large-file transfer application, affecting versions 6.15-7 and prior. A remote attacker who holds valid credentials can manipulate path parameters in dropoff requests to traverse outside the intended directories. Successful exploitation lets the attacker retrieve files dropped off by other ZendTo users, read files elsewhere on the host system (potentially exposing configuration or credential material), or cause a denial of service. Any organization running ZendTo 6.15-7 or an earlier version is affected, particularly those that expose the web interface to the internet. The flaw is not yet listed in CISA's KEV and no public PoC is known, but the 69.1% EPSS score (99th percentile) indicates a high probability of exploitation attempts within the next 30 days.

What to do: Upgrade ZendTo to the latest release available (any version newer than 7, published after this advisory), as no fixed version is specified in the data. If you run ZendTo, verify your deployed version, restrict dropoff access to trusted authenticated users, and review dropoff/audit logs for anomalous path parameters or unexpected file reads. Until patched, limit internet exposure of the ZendTo interface and avoid using it to transfer sensitive files.

Affected
ZendTo (open-source project) ZendTo6.15-7 and prior
Estimated exposure
nichelikely hundreds to low thousands of self-hosted instances — ZendTo is a niche, self-hosted file-transfer application deployed mainly by universities and small-to-mid-sized organizations, so internet-exposed installations in public scans typically number in the hundreds to low thousands.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A path traversal vulnerability exists in the file dropoff functionality of ZendTo versions 6.15-7 and prior. This could allow a remote, authenticated attacker to retrieve the files of other ZendTo users, retrieve files on the host system, or cause a denial of service.

Weakness
CWE-22
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news