Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 20 Aug 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to accurately guess or brute-force the generated filename within a short time window. An attacker can successfully locate and access uploaded files, which can be used to facilitate further attacks. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch. | |
| Title | Weak File Name Generation in vsDesk | |
| Weaknesses | CWE-340 CWE-377 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Kaspersky
Published:
Updated: 2026-08-20T06:39:04.669Z
Reserved: 2025-12-12T18:42:14.784Z
Link: CVE-2025-14602
No data.
Status : Received
Published: 2026-08-20T07:16:30.623
Modified: 2026-08-20T07:16:30.623
Link: CVE-2025-14602
No data.
OpenCVE Enrichment
No data.