CVE-2025-49089: HARRY0703 Moneyprinterturbo

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

wangxutech MoneyPrinterTurbo 1.2.6 allows path traversal via /api/v1/download/ URIs such as /api/v1/download//etc/passwd.

Affected products

  • HARRY0703 Moneyprinterturbo: version 1.2.6 only

Published 2025-09-15. Last modified 2026-06-17.