Executive brief
Başarsoft Rotaban, a route management and optimization platform, contains a critical security flaw that allows users to upload malicious files to the server. An attacker can use this to install a 'web shell,' which provides them with full control over the application and the underlying server. This could lead to the theft of sensitive data, total service disruption, or the use of the server as a jumping-off point for further attacks on the corporate network.
Technical details
A vulnerability classified as CWE-434 (Unrestricted Upload of File with Dangerous Type) exists in Başarsoft Rotaban versions V2026.06.002 through V2026.06.003. The application fails to properly validate file extensions or content types during the upload process, allowing an attacker with low-level privileges to upload executable scripts (web shells) to the web server. Because the CVSS vector indicates a scope change (S:C), the exploit likely allows the attacker to move from the web application environment to the host operating system. Successful exploitation results in full system compromise, including unauthorized data access and arbitrary command execution. Users should update to version V2026.06.003 or later to remediate the issue.
Affected products
- Başarsoft Information Technologies Inc. Rotaban V2026.06.002 to V2026.06.003
Timeline
- 2026-06-11: advisory: Advisory published by TR-CERT and NVD