Blog

Vite Arbitrary File Read Vulnerability (CVE-2025-31486)

abril 9, 2025 | NSFOCUS

Overview Recently, NSFOCUS CERT detected that Vite issued a security bulletin to fix the Vite arbitrary file read vulnerability (CVE-2025-31486); Because the Vite development server does not strictly verify the path when processing URL requests, unauthenticated attackers can bypass path access restrictions by constructing special URLs and read arbitrary files on the target server. At […]

Uma imagem que ilustra uma segurança cibernética, como um firewall.

O que é um Firewall? Veja como escolher o melhor em 2025

abril 4, 2025 | Eduardo Guerra

Sabe-se que a segurança é fundamental para os usuários de computadores. Como atualmente estes aparelhos se tornam parte do dia-a-dia, é muito comum ver um aumento nas ameaças à segurança. Na hora de monitorar e filtrar esses possíveis ataques, foi desenvolvido o Firewall, que ajuda a bloquear o acesso não autorizado ou malicioso à redes, […]

Vite Arbitrary File Read Vulnerability (CVE-2025-31125)

abril 3, 2025 | NSFOCUS

Overview Recently, NSFOCUS CERT detected that Vite issued a security bulletin to fix the Vite arbitrary file read vulnerability (CVE-2025-31125); Because the Vite development server does not strictly verify the path when processing URL requests, unauthenticated attackers can bypass path access restrictions by constructing special URLs and read arbitrary files on the target server. At […]

Imagem que ilustra o que é WAF.

New UI for NSFOCUS WAF V6.0R09F00 – Experience a Smoother Site Management

abril 3, 2025 | NSFOCUS

NSFOCUS understands that the Security Operations team is facing increasing threats to their web applications and workloads are rising accordingly, a simple yet easy-to-use WAF has become more important than ever for effective Security Operations. The upcoming NSFOCUS Web Application Firewall (WAF) V6.0R09F00 (hereafter called as 6090) not only comprehensively reconstructs the architecture but also […]

Vite Arbitrary File Read vulnerability (CVE-2025-30208)

março 28, 2025 | NSFOCUS

Overview Recently, NSFOCUS CERT detected that Vite issued a security announcement and fixed the arbitrary file reading vulnerability of Vite (CVE-2025-30208). Since the Vite development server does not strictly verify the path when processing URL requests, unauthenticated attackers can bypass path access restrictions by constructing special URLs to obtain sensitive files outside the project root […]

Uma imagem que possui API escrito no fundo.

O que é uma API? Entenda a importância e suas funções

março 28, 2025 | Eduardo Guerra

As APIs têm sido cada vez mais utilizadas no mundo da tecnologia, mas nem todo mundo sabe exatamente o que elas são e como funcionam.  Uma API é um conjunto de regras e protocolos que permite a comunicação entre diferentes softwares, tornando a integração e a troca dessas informações mais eficientes. Além disso, elas facilitam […]

Kubernetes Ingress-nginx Remote Code Execution Vulnerability (CVE-2025-1974)

março 27, 2025 | NSFOCUS

Overview Recently, NSFOCUS CERT detected that Kubernetes issued a security announcement and fixed the Kubernetes Ingress-nginx remote code execution vulnerability (CVE-2025-1974). The Ingress controller deployed in Kubernetes Pod can be accessed through the network without authentication. When the Admission webhook is open, an unauthenticated attacker can remotely inject any nginx configuration by sending a special […]

Disposal Advisory for Apache Tomcat Remote Code Execution Vulnerability (CVE-2025-24813)

março 25, 2025 | NSFOCUS

Vulnerability Overview Apache Tomcat Remote Code Execution Vulnerability (CVE-2025-24813) NSFOCUS Detection Methods NSFOCUS Remote Security Assessment System (RSAS), Web Vulnerability Scanning System (WVSS) and Network Intrusion Detection System (IDS) have the ability to scan and detect this vulnerability. Users who deploy the above devices are requested to upgrade to the latest version. Upgrade site: NSFOCUS_Product Support Service_Product Upgrade  […]

Next.js Middleware Permission Bypass Vulnerability (CVE-2025-29927)

março 25, 2025 | NSFOCUS

Overview Recently, NSFOCUS CERT detected that Next.js issued a security announcement and fixed the middleware permission bypass vulnerability (CVE-2025-29927). Because Next.js lacks effective verification of the source of the x-middleware-subrequest header, when configuring to use middleware for authentication and authorization, an unauthenticated attacker can bypass system permission controls by manipulating the x-middleware-subrequest header to access […]

Windows File Explorer Spoofing Vulnerability (CVE-2025-24071)

março 19, 2025 | NSFOCUS

Overview Recently, NSFOCUS CERT detected that Microsoft released a security announcement and fixed the spoofing vulnerability of Windows File Explorer (CVE-2025-24071), with a CVSS score of 7.5. Due to the implicit trust and automatic file parsing behavior of .library-ms files by Windows Explorer, unauthenticated attackers can save files by constructing RAR/ZIP with an embedded malicious […]