References https://www.fortra.com/security/advisories/product-security/fi-2025-012 https://nvd.nist.gov/vuln/detail/CVE-2025-10035 https://juejin.cn/post/7597811700284391443 https://starmap.dbappsecurity.com.cn/info/12355 https://github.com/Avento/CVE-2023-0669 https://www.venustech.com.cn/new_type/aqjx/20250929/28865.html https://fortiguard.fortinet.com/cn/outbreak-alert/goanywhere-mft-attack https://yiuwaije.hashnode.dev/cve-2023-0669-goanywhere-mft https://www.tenablecloud.cn/plugins/nessus/265438 https://cve.imfht.com/poc_detail/700c6af101444bce8ac2feadffb9cab1c51c199c https://www.chnhonker.com/4801.html https://www.secevery.com/toBugInfo?id=1972811717534294018 https://censys.com/advisory/cve-2025-10035/ https://arcticwolf.com/resources/blog/cve-2025-10035/ https://cn-sec.com/archives/4500134.html https://www.microsoft.com/en-us/security/blog/2025/10/06/investigating-active-exploitation-of-cve-2025-10035-goanywhere-managed-file-transfer-vulnerability/
Related VulnerabilitiesFortra GoAnywhere MFT /goanywhere/license/Unlicensed.xhtml 权限绕过漏洞(CVE-2025-10035)PoCfortra-filecatalyst-anonymous-access: Fortra FileCatalyst - Anonymous Access(CVE-2025-10035)Fortra GoAnywhere MFT License Servlet反序列化漏洞可能导致命令注入PoCCVE-2023-0669: Fortra GoAnywhere MFT - Remote Code ExecutionPoCCVE-2024-0204: Fortra GoAnywhere MFT - Authentication BypassPoCCVE-2024-5276: Fortra FileCatalyst Workflow <= v5.1.6 - SQL InjectionPoChuatiandongli-oa-downloadfortrace-fileread: 灵当CRM Playforrecord.php 任意文件读取漏洞PoCCVE-2025-10035: GoAnywhere - Authentication BypassPoCgoanywhere-mft-log4j-rce: GoAnywhere Managed File Transfer - Remote Code Execution (Apache Log4j)PoC华天动力 OA /OAapp/jsp/trace_eWebEditor/downloadfortrace.jsp 文件读取漏洞PoC华天动力OA8000 /OAapp/jsp/trace/downloadfortrace.jsp 文件读取漏洞