CVE-2025-15577

An unauthenticated attacker can exploit this vulnerability by manipulating URL to achieve arbitrary file read access.This issue affects Valmet DNA Web Tools: C2022 and older.
Configurations

Configuration 1 (hide)

cpe:2.3:a:valmet:dna:*:*:*:*:*:*:*:*

History

23 Feb 2026, 14:05

Type Values Removed Values Added
References () https://www.valmet.com/company/innovation/advisories/CVE-2025-15577/ - () https://www.valmet.com/company/innovation/advisories/CVE-2025-15577/ - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Valmet
Valmet dna
CPE cpe:2.3:a:valmet:dna:*:*:*:*:*:*:*:*
Summary
  • (es) Un atacante no autenticado puede explotar esta vulnerabilidad manipulando la URL para lograr acceso de lectura de archivos arbitrarios. Este problema afecta a Valmet DNA Web Tools: C2022 y versiones anteriores.

12 Feb 2026, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-12 07:15

Updated : 2026-02-23 14:05


NVD link : CVE-2025-15577

Mitre link : CVE-2025-15577

CVE.ORG link : CVE-2025-15577


JSON object : View

Products Affected

valmet

  • dna
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')