Skip to main content
Vulnerability Database/CVE-2025-15236

CVE-2025-15236: Quantatw Qoca Aim Path Traversal Flaw

CVE-2025-15236 is a path traversal vulnerability in Quantatw Qoca Aim AI Medical Cloud Platform that allows authenticated attackers to read folder names. This article covers technical details, impact, and mitigation.

Updated:

CVE-2025-15236 Overview

CVE-2025-15236 is a Path Traversal vulnerability affecting the QOCA aim AI Medical Cloud Platform developed by Quanta Computer. The flaw allows authenticated remote attackers to enumerate folder names under a specified path by supplying an absolute path to the application. The issue is classified under [CWE-36] Absolute Path Traversal. Successful exploitation discloses directory structure information that should remain restricted to authorized users.

The vulnerability requires valid low-privilege credentials and is reachable over the network. While confidentiality impact is limited to folder name disclosure, the exposed information can support reconnaissance for subsequent attacks against the medical cloud environment.

Critical Impact

Authenticated attackers can read folder names under arbitrary absolute paths on the QOCA aim platform, exposing file system structure that may aid further attacks against a healthcare data environment.

Affected Products

  • Quanta Computer QOCA aim AI Medical Cloud Platform
  • Vendor identifier: quantatw:qoca_aim
  • All versions prior to the vendor-supplied fix (see Taiwan CERT advisory)

Discovery Timeline

  • 2026-01-05 - CVE-2025-15236 published to NVD
  • 2026-01-20 - Last updated in NVD database

Technical Details for CVE-2025-15236

Vulnerability Analysis

The QOCA aim platform exposes an authenticated endpoint that accepts a file system path parameter and returns the names of folders located at that path. The application fails to constrain the supplied path to an expected base directory. An authenticated attacker can submit an absolute path such as a system root or a sensitive application directory and receive a listing of folder names contained within.

The weakness corresponds to [CWE-36] Absolute Path Traversal, a subclass of path traversal where the attacker supplies a fully qualified path rather than relative traversal sequences. Because the application accepts and acts on the absolute path directly, normal ../ filtering provides no protection. The attack vector is network-based and requires low privileges, with no user interaction.

Root Cause

The root cause is missing canonicalization and validation of user-supplied path input before it is passed to directory enumeration routines. The application does not enforce a permitted base directory or reject absolute path prefixes. As a result, any authenticated session can redirect the folder lookup to arbitrary file system locations accessible to the service account.

Attack Vector

An attacker first obtains valid credentials to the QOCA aim platform. The attacker then issues a request to the vulnerable endpoint while supplying an absolute path of interest. The server responds with the folder names located at that path. The attacker iterates through paths to map the file system, identify configuration directories, locate backup folders, and discover other tenant data layouts.

No verified public proof-of-concept is available. Refer to the Taiwan CERT Security Advisory for vendor-coordinated details.

Detection Methods for CVE-2025-15236

Indicators of Compromise

  • Authenticated HTTP requests containing absolute path values such as /, /etc, /var, or Windows drive letters in path parameters submitted to QOCA aim endpoints.
  • Unusual sequences of folder enumeration requests from a single authenticated session within a short time window.
  • Access patterns from accounts that historically interact only with clinical data but begin probing system or configuration paths.

Detection Strategies

  • Inspect application access logs for path parameter values that begin with absolute path separators or drive letters.
  • Correlate authentication events with subsequent path-handling endpoint calls to identify accounts performing reconnaissance.
  • Apply web application firewall rules that reject path parameters containing absolute path prefixes for QOCA aim API routes.

Monitoring Recommendations

  • Enable verbose audit logging on QOCA aim file and directory operations and forward events to a centralized analytics platform.
  • Alert on enumeration of sensitive directories such as configuration, credential storage, and backup locations.
  • Review authenticated user activity for low-privilege accounts performing high volumes of folder listing requests.

How to Mitigate CVE-2025-15236

Immediate Actions Required

  • Apply the vendor-supplied update referenced in the Taiwan CERT Security Advisory as the primary remediation step.
  • Audit existing QOCA aim accounts and revoke unnecessary access, enforcing least privilege for all authenticated users.
  • Rotate credentials for any accounts suspected of misuse and review session activity for unauthorized path enumeration.

Patch Information

Quanta Computer has coordinated a fix through Taiwan CERT. Administrators should consult the Taiwan CERT Security Announcement and the Taiwan CERT Security Advisory for fixed version details and update procedures.

Workarounds

  • Restrict network access to the QOCA aim management and API interfaces using firewall rules or VPN-only access until the patch is applied.
  • Deploy a web application firewall rule that rejects requests where path parameters begin with / or contain drive letter prefixes such as C:\.
  • Enforce strong authentication and multi-factor authentication on all QOCA aim user accounts to reduce the pool of attackers who can reach the vulnerable endpoint.
  • Increase logging verbosity and review access patterns daily until the update is deployed across all instances.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.