---
id: CVE-2025-12867
title: >-
  EIP Plus developed by Hundred Plus has an Arbitrary File Uplaod vulnerability,
  allowing privileged remote attackers to upload and execute web shell
  backdoors, thereby enabling arbitrary code execution on the server.
summary: >-
  EIP Plus developed by Hundred Plus has an Arbitrary File Uplaod vulnerability,
  allowing privileged remote attackers to upload and execute web shell
  backdoors, thereby enabling arbitrary code execution on the server.
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-434
published: '2025-11-10'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-12867'
references:
  - url: 'https://www.twcert.org.tw/en/cp-139-10491-004b0-2.html'
    label: twcert@cert.org.tw
  - url: 'https://www.twcert.org.tw/tw/cp-132-10490-2534b-1.html'
    label: twcert@cert.org.tw
  - url: 'https://www.chtsecurity.com/news/20848f61-9db5-44fd-8574-c9d6a54e4010'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00631
epssPercentile: 0.48636
ingestedAt: '2026-10-07T21:54:14.998Z'
---

## Overview

EIP Plus developed by Hundred Plus has an Arbitrary File Uplaod vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
