CVE-2026-3025Disclosure(shuoren / smart_heating_integrated_management_platform)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in ShuoRen Smart Heating Integrated Management Platform 1.0.0. Affected by this vulnerability is an unknown functionality of the file /MP/Service/Webservice/ExampleNodeService.asmx. Executing a manipulation of the argument File can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • smart_heating_integrated_management_platform

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-24); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
smart_heating_integrated_management_platform

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-24: 1Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Technical Details · 2026-02-24: 1Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 102-2402-2702-28
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
Full discourse3 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3025 (CVSS:6.9, HIGH) is Undergoing Analysis. A flaw has been found in ShuoRen Smart Heating Integrated Management Platform 1.0.0. Affected by this vulnerability is a..https://nvd.nist.gov/vuln/detail/CVE-2026-3025 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The text announces the discovery of CVE-2026-3025, detailing its CVSS rating and affected product, with a reference to the NVD entry.

    0000020
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3025 (CVSS:6.9, HIGH) is Undergoing Analysis. A flaw has been found in ShuoRen Smart Heating Integrated Management Platform 1.0.0. Affected by this vulnerability is a..https://nvd.nist.gov/vuln/detail/CVE-2026-3025 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    Announcement of CVE‑2026‑3025, a high‑severity flaw in ShuoRen Smart Heating Integrated Management Platform 1.0.0, currently under analysis with no exploit, patch, or PoC disclosed.

    0000020
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3025 A flaw has been found in ShuoRen Smart Heating Integrated Management Platform 1.0.0. Affected by this vulnerability is an unknown functionality of the file /MP/Service/… https://www.cve.org/CVERecord?id=CVE-2026-3025

    Post summary

    A new vulnerability, CVE-2026-3025, has been identified in ShuoRen Smart Heating Integrated Management Platform 1.0.0, affecting an unknown functionality in the /MP/Service/ file.

    00000113
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appshuorensmart_heating_integrated_management_platform1.0.0--

Explore more