PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-15432 yeqifu CVE debrief

A path traversal vulnerability was found in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3 in the /file/downloadShowFile.action file of the com.yeqifu.sys.controller.FileController component. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability allows for remote exploitation, potentially impacting sensitive data and system integrity. Defenders should verify exposure, assess potential impact, and implement compensating controls. The vulnerability was publicly disclosed, and its details are available, emphasizing the need for immediate review and mitigation.

Vendor
yeqifu
Product
carRental
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-02
Original CVE updated
2026-09-30
Advisory published
2026-01-02
Advisory updated
2026-09-30

Who should care

Defenders responsible for yeqifu carRental deployments should assess exposure and potential impact, as the vulnerability allows for remote exploitation and has been publicly disclosed.

Why it matters

CVE-2025-15432 is a path traversal vulnerability in yeqifu carRental that allows remote exploitation. Defenders should verify exposure, assess impact, and implement compensating controls.

  • Verify exposure and assess potential impact on sensitive data and system integrity
  • Implement compensating controls to limit exploitation
  • Monitor for suspicious activity related to the vulnerable component

Technical summary

The vulnerability affects the function downloadShowFile of the file /file/downloadShowFile.action of the component com.yeqifu.sys.controller.FileController. The manipulation of the argument path leads to path traversal. This vulnerability allows remote attackers to access files outside the intended directory, potentially leading to sensitive information disclosure or system compromise. The vulnerability was found in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3, and specific version information for affected or updated releases is not available due to the rolling release model used by the product.

Defensive priority

Defenders should prioritize verifying exposure and assessing potential impact, as the vulnerability allows for remote exploitation and has been publicly disclosed.

Recommended defensive actions

  • Verify exposure by checking system versions and configurations
  • Assess potential impact on sensitive data and system integrity
  • Implement compensating controls to limit exploitation
  • Monitor for suspicious activity related to the vulnerable component
  • Review vendor guidance for patching or mitigation strategies
  • Conduct an asset inventory to identify potentially affected systems
  • Track exceptions and retest remediated assets to ensure vulnerability resolution

Evidence notes

The vulnerability was found in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. The exploit has been disclosed to the public and may be used. However, specific version information for affected or updated releases is not available due to the rolling release model used by the product.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-15432 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-15432

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-15432 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-15432

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.