---
id: CVE-2025-11948
title: >-
  Document Management System developed by Excellent Infotek has an Arbitrary
  File Upload vulnerability, allowing unauthenticated remote attackers to upload
  and execute web shell backdoors, thereby enabling arbitrary code execution on
  the s…
summary: >-
  Document Management System developed by Excellent Infotek has an Arbitrary
  File Upload vulnerability, allowing unauthenticated remote attackers to upload
  and execute web shell backdoors, thereby enabling arbitrary code execution on
  the s…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-434
published: '2025-10-20'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:10:00.563'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11948'
references:
  - url: 'https://www.twcert.org.tw/en/cp-139-10453-43e63-2.html'
    label: twcert@cert.org.tw
  - url: 'https://www.twcert.org.tw/tw/cp-132-10452-72cb6-1.html'
    label: twcert@cert.org.tw
  - url: 'https://www.chtsecurity.com/news/3575ad9c-31f4-49de-8bc4-de85bb2eed39'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01011
epssPercentile: 0.62061
ingestedAt: '2026-10-08T22:11:53.813Z'
---

## Overview

Document Management System developed by Excellent Infotek has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
