Junglewise Threat Intelligence

CVE-2025-14602: vsDesk weak file name generation

CVE-2025-14602 · Severity: info · CVSS 5.3 · Published 2026-08-20

Technologies: vsDesk. Vendors: vsDesk.

Executive brief

vsDesk is a remote support and file-sharing application. The application generates uploaded file names using predictable timestamps, allowing attackers to guess or brute-force filenames and access files that were meant to be confidential. This could enable further attacks such as accessing sensitive documents or leveraging the uploaded files to compromise systems.

Technical details

vsDesk contains an insecure file name generation vulnerability (CWE-330: Use of Insufficiently Random Values) where uploaded files are named using weak, timestamp-based methods. The vulnerability is network-reachable and requires authentication (PR:L). An attacker can accurately predict or brute-force generated filenames within a short time window to access uploaded files that should be confidential. The attack vector is network-based with low attack complexity. Versions 14.0101 and later contain the fix.

Affected products

  • vsDesk vsDesk 11.06.02 through 14.0100

Timeline

  • 2026-08-20: disclosed
  • 2026-08-20: patched: Fixed in versions 14.0101 and later

References

Related threats