External risk intelligence

AndSoft e-TMS OS Command Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-59741

The vulnerability exists in a login-related page (/CLT/LOGINERRORFRM.ASP) of a Transport Management System (e-TMS). As a web-based application interface handling login processes, it is commonly deployed as an internet-facing service or portal to allow remote access for users and logistics partners, making public network reachability a standard deployment pattern for this type of software.

OS Command Injection

Andsoft E Tms

25.03

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical operating system command injection vulnerability has been identified in AndSoft's e-TMS software. This flaw could allow unauthorized individuals to execute commands on the server without needing any credentials by exploiting a specific parameter in the login error form. The main concern at this time is confirming if our specific environment is affected and to what extent.

  • Issue: Attackers can run commands on servers.
  • Why remember: Affects transport management systems.
  • Executive takeaway: Confirm relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a malicious POST request to the affected server. This request targets a specific parameter within the login error form, allowing the attacker to inject operating system commands that are then executed on the server. The vulnerability is present in the e-TMS system, and successful exploitation could grant the attacker significant control over the compromised server.

  • Accessible via the internet.
  • Triggered by sending a POST request.
  • Enables remote command execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to execute arbitrary operating system commands on the server. This may occur when an attacker sends a specially crafted POST request to the `/CLT/LOGINERRORFRM.ASP` endpoint, specifically targeting the 'm' parameter. Such actions could potentially impact the integrity and availability of the server and its hosted services.

  • Server-side operating system commands.
  • Sending malicious POST requests.
  • Compromised server operations.

Operational Fix

Recommended remediation, mitigation, and detection steps

The real-world impact of this operating system command injection vulnerability falls on the teams responsible for the AndSoft e-TMS application and its underlying infrastructure. The first critical step is to identify all instances of e-TMS within the environment, assess their exposure to external networks, and confirm their business criticality. Once accountable owners are identified, a remediation plan can be developed, prioritizing systems that are both exposed and critical.

  • Application owners should lead remediation efforts.
  • Verify external reachability and business criticality.
  • Plan and coordinate urgent maintenance for fixes.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is AndSoft e-TMS?

AndSoft e-TMS is a Transport Management System. Organizations use this software to manage logistics operations, shipping, and supply chain data, often relying on it as a web-based portal to coordinate activities between internal teams and external logistics partners.

How does CVE-2025-59741 create a security weakness?

This vulnerability is an OS command injection flaw, categorized under CWE-77 and CWE-78. It means the application fails to safely filter user-supplied input, allowing an attacker to inject and execute their own operating system commands directly on the server hosting the software.

Does any specific action trigger this vulnerability?

Yes, an attacker can trigger the bug by sending a specially crafted POST request to the specific file /CLT/LOGINERRORFRM.ASP. The exploit relies on injecting malicious code into the 'm' parameter. Requests sent via other methods or targeting different endpoints do not trigger this command injection.

Why is this vulnerability relevant to my network?

Halo Surface Signal notes that since e-TMS is a logistics portal, it is commonly deployed as an internet-facing service for remote user access. Because it is reachable from public networks, systems running the affected version are at higher risk of unauthorized remote exploitation.

What are the first steps to address this CVE?

Your priority is to identify every instance of e-TMS running in your environment. Once identified, confirm which instances are accessible from the internet and evaluate their business criticality to coordinate with system owners on urgent maintenance and patching schedules.