CVE-2025-34181 - CVE House
Back to Database
Status published High CVE-2025-34181

NetSupport Manager < 14.12.0001 Authenticated Path Traversal Arbitrary File Write RCE

Vulnerability Description

NetSupport Manager < 14.12.0001 contains an arbitrary file write vulnerability in its Connectivity Server/Gateway PUTFILE request handler. An attacker with a valid Gateway Key can supply a crafted filename containing directory traversal sequences to write files to arbitrary locations on the server. This can be leveraged to place attacker-controlled DLLs or executables in privileged paths and achieve remote code execution in the context of the NetSupport Manager connectivity service.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-34181

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Chris Leech

Affected Vendor

NetSupport Software

View all reports →

Affected Software

Manager
Vulnerable Versions:
0

Timeline

Official Publish: December 15th, 2025
Last Modified: May 14th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)