CVE-2025-5387: Huayi-Tec Jeewms

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability classified as critical has been found in JeeWMS up to 20250504. Affected is the function dogenerate of the file /generateController.do?dogenerate of the component File Handler. The manipulation leads to improper access controls. It is possible to launch the attack remotely. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.

Affected products

  • Huayi-Tec Jeewms: up to and including 2025-05-04

Published 2025-05-31. Last modified 2026-06-17.