{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-80233",
        "assignerOrgId": "cded6c7f-6ce5-4948-8f87-aa7a3bbb6b0e",
        "state": "PUBLISHED",
        "assignerShortName": "twcert",
        "dateReserved": "2026-08-26T05:58:48.754Z",
        "datePublished": "2026-08-26T08:19:40.187Z",
        "dateUpdated": "2026-08-26T08:22:47.735Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "cded6c7f-6ce5-4948-8f87-aa7a3bbb6b0e",
                "shortName": "twcert",
                "dateUpdated": "2026-08-26T08:22:47.735Z"
            },
            "title": "CAYIN Technology｜CAYIN CMS-WS/CMS-SE/SMP  - Arbitrary File Upload",
            "datePublic": "2026-08-26T08:03:00.000Z",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-434",
                            "description": "CWE-434 Unrestricted Upload of File with Dangerous Type",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-650",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-650 Upload a Web Shell to a Web Server"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "CAYIN Technology",
                    "product": "CAYIN CMS-WS",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThanOrEqual": "1.0.25336",
                            "versionType": "custom"
                        }
                    ],
                    "defaultStatus": "unaffected"
                },
                {
                    "vendor": "CAYIN Technology",
                    "product": "CAYIN CMS-SE",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThanOrEqual": "11.0.25336",
                            "versionType": "custom"
                        }
                    ],
                    "defaultStatus": "unaffected"
                },
                {
                    "vendor": "CAYIN Technology",
                    "product": "CAYIN SMP",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThanOrEqual": "4.0.25336",
                            "versionType": "custom"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "CAYIN CMS-WS, CMS-SE, and SMP series products developed by CAYIN Technology have an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shells backdoors, thereby enabling arbitrary code execution on the server.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<p>CAYIN CMS-WS, CMS-SE, and SMP series products developed by CAYIN Technology have an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shells backdoors, thereby enabling arbitrary code execution on the server.</p>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://www.twcert.org.tw/tw/cp-132-11129-4a040-1.html",
                    "tags": [
                        "third-party-advisory"
                    ]
                },
                {
                    "url": "https://www.twcert.org.tw/en/cp-139-11135-189f7-2.html",
                    "tags": [
                        "third-party-advisory"
                    ]
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_1": {
                        "version": "3.1",
                        "attackVector": "NETWORK",
                        "attackComplexity": "LOW",
                        "privilegesRequired": "HIGH",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "HIGH",
                        "availabilityImpact": "HIGH",
                        "baseSeverity": "HIGH",
                        "baseScore": 7.2,
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
                    }
                },
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV4_0": {
                        "attackVector": "NETWORK",
                        "attackComplexity": "LOW",
                        "attackRequirements": "NONE",
                        "privilegesRequired": "HIGH",
                        "userInteraction": "NONE",
                        "vulnConfidentialityImpact": "HIGH",
                        "subConfidentialityImpact": "NONE",
                        "vulnIntegrityImpact": "HIGH",
                        "subIntegrityImpact": "NONE",
                        "vulnAvailabilityImpact": "HIGH",
                        "subAvailabilityImpact": "NONE",
                        "exploitMaturity": "NOT_DEFINED",
                        "Safety": "NOT_DEFINED",
                        "Automatable": "NOT_DEFINED",
                        "Recovery": "NOT_DEFINED",
                        "valueDensity": "NOT_DEFINED",
                        "vulnerabilityResponseEffort": "NOT_DEFINED",
                        "providerUrgency": "NOT_DEFINED",
                        "version": "4.0",
                        "baseSeverity": "HIGH",
                        "baseScore": 8.6,
                        "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
                    }
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "value": "Update CMS-WS to version 1.0.26198 or later\n\n\n\nUpdate CMS-SE to version 11.0.26198 or later\n\n\n\nUpdate SMP to version 4.0.26198 or later",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<p>Update CMS-WS to version 1.0.26198 or later</p><p>Update CMS-SE to version 11.0.26198 or later</p><p>Update SMP to version 4.0.26198 or later</p>"
                        }
                    ]
                }
            ],
            "source": {
                "advisory": "TVN-202608008",
                "discovery": "EXTERNAL"
            },
            "x_generator": {
                "engine": "TWCERT TVN Workbench"
            }
        }
    }
}