---
id: CVE-2025-34163
title: >-
  Dongsheng Logistics Software exposes an unauthenticated endpoint at
  /CommMng/Print/UploadMailFile that fails to enforce proper file type
  validation and access control
summary: >-
  Dongsheng Logistics Software exposes an unauthenticated endpoint at
  /CommMng/Print/UploadMailFile that fails to enforce proper file type
  validation and access control. An attacker can upload arbitrary files,
  including executable scripts …
severity: none
cwe:
  - CWE-434
published: '2025-08-27'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-34163'
references:
  - url: 'http://www.dongshengsoft.com/'
    label: disclosure@vulncheck.com
  - url: 'https://cn-sec.com/archives/4243708.html'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/dongsheng-logisitics-software-unauth-arbitrary-file-upload
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00654
epssPercentile: 0.49181
ingestedAt: '2026-08-05T11:47:23.555Z'
---

## Overview

Dongsheng Logistics Software exposes an unauthenticated endpoint at /CommMng/Print/UploadMailFile that fails to enforce proper file type validation and access control. An attacker can upload arbitrary files, including executable scripts such as .ashx, via a crafted multipart/form-data POST request. This allows remote code execution on the server, potentially leading to full system compromise. The vulnerability is presumed to affect builds released prior to July 2025 and is remediated in newer versions of the product, though the exact affected range remains undefined. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-07-23 UTC.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
