CVE-2025-14602
Received Received - Intake

Predictable Filename Generation in VSDesk Software

Vulnerability report for CVE-2025-14602, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-20

Last updated on: 2026-08-20

Assigner: Kaspersky Labs

Description

The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to accurately guess or brute-force the generated filename within a short time window.Β An attacker can successfully locate and access uploaded files, which can be used to facilitate further attacks. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-20
Last Modified
2026-08-20
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-340 The product uses a scheme that generates numbers or identifiers that are more predictable than required.
CWE-377 Creating and using insecure temporary files can leave application and system data vulnerable to attack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The application creates filenames for uploaded files using a weak method based on the request timestamp. This predictability allows attackers to guess or brute-force the filenames within a short timeframe, enabling them to locate and access uploaded files for further malicious activities.

Detection Guidance

This vulnerability involves predictable file upload names based on timestamps. To detect it, monitor file uploads and check if filenames follow a predictable pattern like timestamps. Look for unusual file access patterns or unauthorized file retrieval attempts. No specific commands are provided in the context.

Impact Analysis

An attacker could exploit this to access sensitive files you uploaded, potentially stealing confidential data or using the files to launch additional attacks against you or the system.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR and HIPAA requirements for data protection and confidentiality.

Mitigation Strategies

Apply the vendor patch for versions 14.0101 and above from https://vsdesk.ru/. Ensure uploaded file names are generated using a secure, non-predictable method.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-14602. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart