QOCA aim AI Medical Cloud Platform developed by Quanta Computer has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
References
| Link | Resource |
|---|---|
| https://www.twcert.org.tw/en/cp-139-10616-cd942-2.html | Third Party Advisory |
| https://www.twcert.org.tw/tw/cp-132-10615-157a3-1.html | Third Party Advisory |
Configurations
History
20 Jan 2026, 21:10
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:quantatw:qoca_aim:*:*:*:*:*:*:*:* | |
| First Time |
Quantatw
Quantatw qoca Aim |
|
| References | () https://www.twcert.org.tw/en/cp-139-10616-cd942-2.html - Third Party Advisory | |
| References | () https://www.twcert.org.tw/tw/cp-132-10615-157a3-1.html - Third Party Advisory |
05 Jan 2026, 09:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-05 09:15
Updated : 2026-01-20 21:10
NVD link : CVE-2025-15240
Mitre link : CVE-2025-15240
CVE.ORG link : CVE-2025-15240
JSON object : View
Products Affected
quantatw
- qoca_aim
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
