CVE-2025-2155
Deferred
Deferred - Pending Action
Unrestricted File Upload in Specto CM Enables Remote Code Execution
Publication date: 2025-12-24
Last updated on: 2026-06-06
Assigner: Computer Emergency Response Team of the Republic of Turkey
Description
Description
Unrestricted Upload of File with Dangerous Type vulnerability in Echo Call Center Services Trade and Industry Inc. Specto CM allows Remote Code Inclusion.
This issue affects Specto CM: before 17032025.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| echo_call_center_services_trade_and_industry_inc | specto_cm | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-434 | The product allows the upload or transfer of dangerous file types that are automatically processed within its environment. |