---
id: CVE-2025-13282
title: >-
  TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Delete
  vulnerability
summary: >-
  TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Delete
  vulnerability. The application sets up a simple local web server and provides
  APIs for communication with the target website. Due to the lack of CSRF
  protection …
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H'
cwe:
  - CWE-36
  - CWE-352
vendor: cht
product: tenderdoctransfer
affected:
  - tenderdoctransfer < 0.41.159
patched:
  - tenderdoctransfer 0.41.159
published: '2025-11-17'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13282'
references:
  - url: 'https://www.twcert.org.tw/en/cp-139-10511-10f3a-2.html'
    label: twcert@cert.org.tw
  - url: 'https://www.twcert.org.tw/tw/cp-132-10510-3719c-1.html'
    label: twcert@cert.org.tw
tags:
  - nvd
epss: 0.00266
epssPercentile: 0.17002
ingestedAt: '2026-10-07T21:54:15.051Z'
---

## Overview

TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could use these APIs through phishing. Additionally, one of the APIs contains an Absolute Path Traversal vulnerability, allowing attackers to delete arbitrary files on the user's system.

## Affected

- `tenderdoctransfer < 0.41.159`

## Remediation

Upgrade past the affected range:

- `tenderdoctransfer 0.41.159`
