CVE-2025-34508: Zendto

Medium severity, CVSS 6.3. EPSS: 73.2% chance of exploitation in the next 30 days.

A path traversal vulnerability exists in the file dropoff functionality of ZendTo versions 6.15-7 and prior. This could allow a remote, authenticated attacker to retrieve the files of other ZendTo users, retrieve files on the host system, or cause a denial of service.

Affected products

  • Zendto Zendto: before 6.15-8 (fixed in 6.15-8)

Published 2025-06-17. Last modified 2026-06-17.