CVE-2025-67260
The Terrapack software, from ASTER TEC / ASTER S.p.A., with the indicated components and versions has a file upload vulnerability that may allow attackers to execute arbitrary code. Vulnerable components include Terrapack TkWebCoreNG:: 1.0.20200914, Terrapack TKServerCGI 2.5.4.150, and Terrapack TpkWebGIS Client 1.0.0.
Published:Mar 20, 2026
Last Modified:Apr 14, 2026
EPS:Mar 20, 2026
EPSS Score:0.00067
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
Aster
Product
Tkservercgi
Aster
Tkservercgi
Vendor
Aster
Product
Tkwebcoreng
Aster
Tkwebcoreng
Vendor
Aster
Product
Tpkwebgis Client
Aster
Tpkwebgis Client
Vendor
Aster-te
Product
Terrapack Tkservercgi
Aster-te
Terrapack Tkservercgi
Vendor
Aster-te
Product
Terrapack Tkwebcoreng
Aster-te
Terrapack Tkwebcoreng
Vendor
Aster-te
Product
Terrapack Tpkwebgis
Aster-te
Terrapack Tpkwebgis
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
