The Terrapack software, from ASTER TEC / ASTER S.p.A., with the indicated components and versions has a file upload vulnerability that may allow attackers to execute arbitrary code. Vulnerable components include Terrapack TkWebCoreNG:: 1.0.20200914, Terrapack TKServerCGI 2.5.4.150, and Terrapack TpkWebGIS Client 1.0.0.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 23 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aster
Aster tkservercgi Aster tkwebcoreng Aster tpkwebgis Client |
|
| Vendors & Products |
Aster
Aster tkservercgi Aster tkwebcoreng Aster tpkwebgis Client |
Fri, 20 Mar 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Terrapack software, from ASTER TEC / ASTER S.p.A., with the indicated components and versions has a file upload vulnerability that may allow attackers to execute arbitrary code. Vulnerable components include Terrapack TkWebCoreNG:: 1.0.20200914, Terrapack TKServerCGI 2.5.4.150, and Terrapack TpkWebGIS Client 1.0.0. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-03-20T15:38:37.869Z
Reserved: 2025-12-08T00:00:00.000Z
Link: CVE-2025-67260
No data.
Status : Received
Published: 2026-03-20T16:16:16.490
Modified: 2026-03-20T16:16:16.490
Link: CVE-2025-67260
No data.
OpenCVE Enrichment
Updated: 2026-03-23T09:54:20Z
Weaknesses
No weakness.