Executive brief
Dongsheng Logistics Software, a platform used for managing international shipping, warehousing, and freight operations, contains a critical security flaw in its file handling component. An unauthorized person can upload malicious files to the server without needing a username or password. If exploited, this allows an attacker to take complete control of the server, potentially leading to the theft of sensitive logistics data, disruption of shipping operations, or the deployment of ransomware.
Technical details
An unauthenticated arbitrary file upload vulnerability exists in Dongsheng Logistics Software due to insufficient file type validation and lack of access control on the '/CommMng/Print/UploadMailFile' endpoint. An attacker can send a specially crafted multipart/form-data POST request to upload executable scripts, such as .ashx files, directly to the web server. Because the endpoint does not require authentication, any network-reachable instance is vulnerable. Successful exploitation allows for Remote Code Execution (RCE) under the context of the web service, potentially leading to full system compromise. The vulnerability is remediated in builds released after July 2025.
Affected products
- Dongsheng (Dongsheng Weiye) Logistics Software Builds released prior to July 2025
Timeline
- 2025-07-16: disclosed: Initial disclosure by CN-SEC/Qian'an Security
- 2025-07-23: exploited: Exploitation evidence first observed by Shadowserver Foundation
- 2025-08-27: advisory: VulnCheck and NVD published advisory details