CVE advisoryCRITICAL
CVE-2025-59741
AndSoft e-TMS OS Command Injection Vulnerability
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A critical operating system command injection vulnerability in AndSoft's e-TMS allows unauthenticated attackers to execute server commands via a POST request to the login error form. This could impact server integrity and availability if the vulnerable system is reachable.