PatchSiren

PCViewer CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH PCViewer CVE published 2026-05-25

CVE-2018-25365

CVE-2018-25365 is a directory traversal vulnerability in PCViewer vt1000 that allows unauthenticated remote attackers to read arbitrary files from the underlying system. The vulnerability exists due to insufficient input validation on GET request parameters, enabling attackers to use relative path sequences (e.g., `../../../../../../../../../../../../etc/passwd`) to escape the intended directory and acces [truncated]