A flaw has been found in ShuoRen Smart Heating Integrated Management Platform 1.0.0. Affected by this vulnerability is an unknown functionality of the file /MP/Service/Webservice/ExampleNodeService.asmx. Executing a manipulation of the argument File can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Tue, 24 Feb 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Shuoren
Shuoren smart Heating Integrated Management Platform |
|
| Vendors & Products |
Shuoren
Shuoren smart Heating Integrated Management Platform |
Mon, 23 Feb 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in ShuoRen Smart Heating Integrated Management Platform 1.0.0. Affected by this vulnerability is an unknown functionality of the file /MP/Service/Webservice/ExampleNodeService.asmx. Executing a manipulation of the argument File can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | ShuoRen Smart Heating Integrated Management Platform ExampleNodeService.asmx unrestricted upload | |
| Weaknesses | CWE-284 CWE-434 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-02-23T20:02:07.178Z
Updated: 2026-02-23T20:02:07.178Z
Reserved: 2026-02-23T13:59:09.845Z
Link: CVE-2026-3025
No data.
Status : Awaiting Analysis
Published: 2026-02-23T21:19:12.497
Modified: 2026-02-24T14:13:49.320
Link: CVE-2026-3025
No data.