Executive brief
Terrapack is a specialized GIS and simulation platform used for managing territorial infrastructure and IoT data. A security flaw in its file management component allows authorized users to upload malicious files to the server. If successfully exploited, an attacker could take full control of the system, potentially disrupting public services or accessing sensitive infrastructure data.
Technical details
An unrestricted file upload vulnerability (CWE-434) exists in the Terrapack WebGIS platform. The 'TkWebCoreNG/InputOutputFile.php' page fails to implement sufficient server-side validation, allowing authenticated users to upload arbitrary files. These files are stored in the 'TkRepository' directory. If an attacker can subsequently access or execute these uploaded files, they can achieve Remote Code Execution (RCE). The vendor recommends deploying the software in air-gapped or highly secured environments to mitigate exposure.
Affected products
- ASTER TEC / ASTER S.p.A. Terrapack TkWebCoreNG 1.0.20200914
- ASTER TEC / ASTER S.p.A. Terrapack TKServerCGI 2.5.4.150
- ASTER TEC / ASTER S.p.A. Terrapack TpkWebGIS Client 1.0.0
Timeline
- 2025-04: disclosed: Vulnerability discovered and reported to vendor by Telsy SpA and Alten Italia SpA.
- 2025-05: other: Reported to Italian national CSIRT.
- 2026-03-20: advisory: Initial NVD publication.