CVE-2025-69620

A path traversal in Moo Chan Song v4.5.7 allows attackers to cause a Denial of Service (DoS) via writing files to the internal storage.
References
Link Resource
http://www.ntoolslab.com/ Product
https://github.com/Secsys-FDU/AF_CVEs/issues/11 Exploit Third Party Advisory
https://secsys.fudan.edu.cn/ Not Applicable
Configurations

Configuration 1 (hide)

cpe:2.3:a:ntoolslab:office_reader:4.5.7:*:*:*:*:android:*:*

History

05 Jul 2026, 02:17

Type Values Removed Values Added
References
  • {'url': 'http://office.com', 'tags': ['Not Applicable'], 'source': 'cve@mitre.org'}

17 Jun 2026, 10:00

Type Values Removed Values Added
Summary
  • (es) Un salto de ruta en Moo Chan Song v4.5.7 permite a los atacantes causar una denegación de servicio (DoS) mediante la escritura de archivos en el almacenamiento interno.

11 Feb 2026, 19:02

Type Values Removed Values Added
CPE cpe:2.3:a:ntoolslab:office_reader:4.5.7:*:*:*:*:android:*:*
References () http://office.com - () http://office.com - Not Applicable
References () http://www.ntoolslab.com/ - () http://www.ntoolslab.com/ - Product
References () https://github.com/Secsys-FDU/AF_CVEs/issues/11 - () https://github.com/Secsys-FDU/AF_CVEs/issues/11 - Exploit, Third Party Advisory
References () https://secsys.fudan.edu.cn/ - () https://secsys.fudan.edu.cn/ - Not Applicable
First Time Ntoolslab office Reader
Ntoolslab

09 Feb 2026, 18:16

Type Values Removed Values Added
CWE CWE-400 CWE-22
CVSS v2 : unknown
v3 : 5.7
v2 : unknown
v3 : 5.0

05 Feb 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 5.7

04 Feb 2026, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-400

04 Feb 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-04 02:16

Updated : 2026-07-05 02:17


NVD link : CVE-2025-69620

Mitre link : CVE-2025-69620

CVE.ORG link : CVE-2025-69620


JSON object : View

Products Affected

ntoolslab

  • office_reader
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')