Executive brief
Specto CM, a call center management platform, contains a security flaw that allows users to upload dangerous file types to the server. An attacker with basic user access could exploit this to run unauthorized code, potentially leading to a full system takeover, data theft, or service disruption. This vulnerability poses a significant risk to the confidentiality and integrity of call center operations and customer data.
Technical details
An unrestricted upload of a file with a dangerous type (CWE-434) exists in Echo Call Center Services Specto CM. The vulnerability allows a remote attacker with low-level authenticated privileges to upload malicious scripts or executables to the server. Because the application fails to properly validate or sanitize uploaded file extensions and content, these files can be executed by the server, leading to Remote Code Execution (RCE). The issue is addressed in versions released on or after March 17, 2025 (17032025).
Affected products
- Echo Call Center Services Trade and Industry Inc. Specto CM before 17032025
Timeline
- 2025-12-24: disclosed
- 2025-12-24: advisory