PatchSiren cyber security CVE debrief
CVE-2025-15432 yeqifu CVE debrief
A path traversal vulnerability was found in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3 in the /file/downloadShowFile.action file of the com.yeqifu.sys.controller.FileController component. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability allows for remote exploitation, potentially impacting sensitive data and system integrity. Defenders should verify exposure, assess potential impact, and implement compensating controls. The vulnerability was publicly disclosed, and its details are available, emphasizing the need for immediate review and mitigation.
- Vendor
- yeqifu
- Product
- carRental
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-02
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-01-02
- Advisory updated
- 2026-09-30
Who should care
Defenders responsible for yeqifu carRental deployments should assess exposure and potential impact, as the vulnerability allows for remote exploitation and has been publicly disclosed.
Why it matters
CVE-2025-15432 is a path traversal vulnerability in yeqifu carRental that allows remote exploitation. Defenders should verify exposure, assess impact, and implement compensating controls.
- Verify exposure and assess potential impact on sensitive data and system integrity
- Implement compensating controls to limit exploitation
- Monitor for suspicious activity related to the vulnerable component
Technical summary
The vulnerability affects the function downloadShowFile of the file /file/downloadShowFile.action of the component com.yeqifu.sys.controller.FileController. The manipulation of the argument path leads to path traversal. This vulnerability allows remote attackers to access files outside the intended directory, potentially leading to sensitive information disclosure or system compromise. The vulnerability was found in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3, and specific version information for affected or updated releases is not available due to the rolling release model used by the product.
Defensive priority
Defenders should prioritize verifying exposure and assessing potential impact, as the vulnerability allows for remote exploitation and has been publicly disclosed.
Recommended defensive actions
- Verify exposure by checking system versions and configurations
- Assess potential impact on sensitive data and system integrity
- Implement compensating controls to limit exploitation
- Monitor for suspicious activity related to the vulnerable component
- Review vendor guidance for patching or mitigation strategies
- Conduct an asset inventory to identify potentially affected systems
- Track exceptions and retest remediated assets to ensure vulnerability resolution
Evidence notes
The vulnerability was found in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. The exploit has been disclosed to the public and may be used. However, specific version information for affected or updated releases is not available due to the rolling release model used by the product.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-15432 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-15432
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-15432 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-15432
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/yeqifu/carRental/
-
Source reference
Unverified legacy reference
URL: https://github.com/yeqifu/carRental/issues/46
[email protected] - Exploit, Issue Tracking, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.