CVE-2025-34508: Zendto
Medium severity, CVSS 6.3. EPSS: 73.2% chance of exploitation in the next 30 days.
A path traversal vulnerability exists in the file dropoff functionality of ZendTo versions 6.15-7 and prior. This could allow a remote, authenticated attacker to retrieve the files of other ZendTo users, retrieve files on the host system, or cause a denial of service.
Affected products
- Zendto Zendto: before 6.15-8 (fixed in 6.15-8)
Published 2025-06-17. Last modified 2026-06-17.