go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

ThinPLUS|ThinPLUS - OS Command Injection

TVN ID TVN-202511010
CVE ID CVE-2025-13284
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products ThinPLUS TPmCloud4.0
Description ThinPLUS developed by ThinPLUS has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.
Solution Please update to version TPmCloud4.2 or later.
Credit Ding(DEVCORE)
Public Date 2025-11-17
Top