CVE-2025-10468: Path Traversal in Beyaz Computer's CityPLus
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Beyaz Computer CityPlus allows Path Traversal.
This issue affects CityPlus: before 24.29375.
Security readout for executives and security teams
Plain-English summary
CVE-2025-10468 is a path traversal flaw in Beyaz Computer CityPlus. An unauthenticated remote attacker could potentially read files outside intended directories. The published impact is confidentiality loss, not system takeover. CityPlus versions before 24.29375 are listed as affected.
Executive priority
Treat as high priority if CityPlus is deployed, because the flaw may allow unauthenticated remote file disclosure. Prioritize confirming whether the product exists in your environment and upgrading affected versions. Urgency is lower if CityPlus is absent or isolated from untrusted networks.
Technical view
The issue is CWE-22: improper limitation of a pathname to a restricted directory. CVSS 3.1 is 7.5: network-accessible, low complexity, no privileges, no user interaction, unchanged scope, high confidentiality impact, no integrity or availability impact.
Likely exposure
Exposure is limited to organizations running Beyaz Computer CityPlus before 24.29375, especially if accessible over a network or the internet. The sources do not identify specific modules, endpoints, deployment models, or default exposure.
Exploitation context
CISA KEV status is false in the provided bundle, and the cited sources do not state active exploitation. The CVSS vector indicates exploitation could be remote and unauthenticated, but public exploit availability is not established by the provided evidence.
Researcher notes
Public details are sparse. The record names path traversal and affected versions before 24.29375, but does not provide affected endpoints, proof-of-concept details, or exploit telemetry. Avoid assuming broader impact beyond confidentiality unless vendor guidance adds evidence.
Mitigation direction
Inventory all Beyaz Computer CityPlus deployments and owners.
Upgrade CityPlus to 24.29375 or a later non-affected version.
If upgrading is delayed, restrict network access to CityPlus.
Review Beyaz Computer or Turkish government advisory guidance for official instructions.
Increase monitoring for unexpected file access or disclosure events.
Validation and detection
Confirm installed CityPlus versions are 24.29375 or later.
Identify any internet-facing CityPlus instances.
Check access controls limiting CityPlus to trusted networks.
Review application and web server logs for unusual file read patterns.
Track vendor or government advisories for updated remediation details.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-22: File access and web shell behavior lookup
File traversal and upload weaknesses can lead teams to review file, web shell, execution, and collection telemetry. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references file access or upload behavior, so file telemetry and web shell review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.