Junglewise Threat Intelligence

CVE-2025-69612: TMS Global Software TMS Management Console path traversal in Download Template

CVE-2025-69612 · Severity: medium · CVSS 6.5 · Published 2026-01-22

Executive brief

TMS Management Console, a platform used by financial institutions to manage and monitor ATM networks, contains a security flaw in its template download feature. An authorized user can exploit this weakness to access sensitive system files that should be restricted. This could lead to the exposure of critical configuration data, potentially compromising the security and integrity of the ATM management infrastructure.

Technical details

A path traversal vulnerability exists in the TMS Management Console (version 6.3.7.27386.20250818 and earlier) within the 'Download Template' function of the profile dashboard. The vulnerability is located in the /Home/DownloadFileByPath API endpoint, which fails to properly sanitize the 'filePath' parameter for directory traversal sequences like '../'. An authenticated attacker can exploit this to read arbitrary files from the server's file system, including sensitive configuration files such as Web.config. This is a remote, network-based attack that requires low-level user privileges but no user interaction.

Affected products

  • TMS Global Software TMS Management Console <= 6.3.7.27386.20250818

Timeline

  • 2025-01-22: disclosed
  • 2025-01-22: advisory

References