| TVN ID | TVN-202608008 |
|---|---|
| CVE ID | CVE-2026-80233 |
| CVSS | 7.2 (High) CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| Affected Products | CMS-WS version 1.0.25336 and earlier CMS-SE version 11.0.25336 and earlier SMP version 4.0.25336 and earlier |
| Description | CAYIN CMS-WS, CMS-SE, and SMP series products developed by CAYIN Technology have an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shells backdoors, thereby enabling arbitrary code execution on the server. |
| Solution | Update CMS-WS to version 1.0.26198 or later Update CMS-SE to version 11.0.26198 or later Update SMP to version 4.0.26198 or later |
| Credit | Jing-Xun Sun |
| Public Date | 2026-08-26 |
