CVE-2025-40625: Tcman Gim

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Unrestricted file upload in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to upload any file within the server, even a malicious file to obtain a Remote Code Execution (RCE).

Affected products

  • Tcman Gim: version 11.0 only

Published 2025-05-06. Last modified 2026-06-17.