{"id":"CVE-2025-14602","title":"The application generates uploaded file names using a weak and predictable method based on the request timestamp","summary":"The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to accurately guess or brute-force the generated filename within a short time window. An atta…","severity":"none","cwe":["CWE-340","CWE-377"],"published":"2026-08-20","updated":"2026-09-29","sourceUpdated":"2026-09-29T10:10:00.263","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-14602","references":[{"url":"https://github.com/klsecservices/Advisories/blob/master/KLSA-00294-Weak-File-Name-Generation-in-vsDesk.md","label":"vulnerability@kaspersky.com"}],"tags":["nvd"],"ingestedAt":"2026-09-29T10:31:36.301Z","epss":0.00465,"epssPercentile":0.37821,"slug":"CVE-2025-14602","body":"## Overview\n\nThe application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to accurately guess or brute-force the generated filename within a short time window. An attacker can successfully locate and access uploaded files, which can be used to facilitate further attacks.\n\n\n\n\nApply patch from vendor  https://vsdesk.ru/ . Versions 14.0101 and on have the patch.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}