CVE-2025-70995Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue in Aranda Service Desk Web Edition (ASDK API 8.6) allows authenticated attackers to achieve remote code execution due to improper validation of uploaded files. An authenticated user can upload a crafted web.config file by sending a crafted POST request to /ASDKAPI/api/v8.6/item/addfile, which is processed by the ASP.NET runtime. The uploaded configuration file alters the execution context of the upload directory, enabling compilation and execution of attacker-controlled code (e.g., generation of an .aspx webshell). This allows remote command execution on the server without user interaction beyond authentication, impacting both On-Premise and SaaS deployments. The vendor has fixed the issue in Aranda Service Desk V8 8.30.6.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-09)
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-05: 1Mentions · 2026-03-08: 1Mentions · 2026-03-09: 2Technical Details · 2026-03-05: 1Technical Details · 2026-03-08: 1Technical Details · 2026-03-09: 203-0503-0803-09
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-051
Disclosure1
2026-03-081
Disclosure1
2026-03-092
Disclosure2
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-70995 An issue in Aranda Service Desk Web Edition (ASDK API 8.6) allows authenticated attackers to achieve remote code execution due to improper validation of uploaded file… https://www.cve.org/CVERecord?id=CVE-2025-70995 ----- Traducción: CVE-2025-70995 Un … http://infoflow.cloud`

    Post summary

    A new CVE (CVE-2025-70995) affecting Aranda Service Desk Web Edition allows authenticated attackers to achieve remote code execution via improper file validation; no exploitation, patch, or PoC is reported.

    0000085
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-70995 An issue in Aranda Service Desk Web Edition (ASDK API 8.6) allows authenticated attackers to achieve remote code execution due to improper validation of uploaded file… https://www.cve.org/CVERecord?id=CVE-2025-70995

    Post summary

    The text provides a brief disclosure of CVE‑2025‑70995, noting that authenticated users can achieve remote code execution through improper uploaded file validation in a specific software version.

    00000228
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-70995 - High An issue in Aranda Service Desk Web Edition (ASDK API 8.6) allows authenticated attackers to achieve remote code execution due to improper validation of uploaded files. An authenticated user ... https://www.thehackerwire.com/vulnerability/CVE-2025-70995/ https://t.co/eHiDyMYPSa

    Post summary

    The post announces the discovery of CVE‑2025‑70995, indicating RCE via uploaded files in Aranda Service Desk Web Edition, but provides no exploit code, PoC, or patch details.

    00000112
    130 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-70995 Remote Code Execution in Aranda Service Desk Web Edition API 8.6 via File Upload https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-70995

    Post summary

    The post announces CVE‑2025‑70995, an RCE vulnerability in Aranda Service Desk Web Edition API 8.6 that can be triggered by a file upload. No PoC, exploit code, active exploitation evidence, or patch information is included.

    0000076
    4.0K followersView on X

Explore more