---
id: CVE-2025-15240
title: >-
  QOCA aim AI Medical Cloud Platform developed by Quanta Computer has an
  Arbitrary File Upload vulnerability, allowing authenticated remote attackers
  to upload and execute web shell backdoors, thereby enabling arbitrary code
  execution on t…
summary: >-
  QOCA aim AI Medical Cloud Platform developed by Quanta Computer has an
  Arbitrary File Upload vulnerability, allowing authenticated remote attackers
  to upload and execute web shell backdoors, thereby enabling arbitrary code
  execution on t…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-434
vendor: quantatw
product: qoca_aim
affected:
  - qoca_aim < 2.7.6
patched:
  - qoca_aim 2.7.6
published: '2026-01-05'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15240'
references:
  - url: 'https://www.twcert.org.tw/en/cp-139-10616-cd942-2.html'
    label: twcert@cert.org.tw
  - url: 'https://www.twcert.org.tw/tw/cp-132-10615-157a3-1.html'
    label: twcert@cert.org.tw
tags:
  - nvd
epss: 0.00508
epssPercentile: 0.41121
ingestedAt: '2026-09-30T23:29:32.534Z'
---

## Overview

QOCA aim AI Medical Cloud Platform developed by Quanta Computer has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

## Affected

- `qoca_aim < 2.7.6`

## Remediation

Upgrade past the affected range:

- `qoca_aim 2.7.6`
