---
id: CVE-2025-65897
title: >-
  zdh_web is a data collection, processing, monitoring, scheduling, and
  management platform
summary: >-
  zdh_web is a data collection, processing, monitoring, scheduling, and
  management platform. In zdh_web thru 5.6.17, insufficient validation of file
  upload paths in the application allows an authenticated user to write
  arbitrary files to t…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
  - CWE-434
vendor: zhaoyachao
product: zdh_web
affected:
  - zdh_web <= 5.6.17
published: '2025-12-05'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-65897'
references:
  - url: 'https://github.com/zhaoyachao/zdh_web'
    label: cve@mitre.org
  - url: >-
      https://github.com/zhaoyachao/zdh_web/commit/b2423378a8bf83f159f19ce4e14eac71c939793a
    label: cve@mitre.org
  - url: 'https://github.com/zhaoyachao/zdh_web/issues/40'
    label: cve@mitre.org
  - url: 'https://github.com/zhaoyachao/zdh_web/pull/39'
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00752
epssPercentile: 0.53081
ingestedAt: '2026-09-25T23:21:16.895Z'
---

## Overview

zdh_web is a data collection, processing, monitoring, scheduling, and management platform. In zdh_web thru 5.6.17, insufficient validation of file upload paths in the application allows an authenticated user to write arbitrary files to the server file system, potentially overwriting existing files and leading to privilege escalation or remote code execution.

## Affected

- `zdh_web <= 5.6.17`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
