Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9xwc-r37w-mmjm

Опубликовано: 13 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authenticity check for uploaded firmware. This can allow attackers to upload crafted firmware which contains backdoors and enables arbitrary code execution.

BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authenticity check for uploaded firmware. This can allow attackers to upload crafted firmware which contains backdoors and enables arbitrary code execution.

EPSS

Процентиль: 50%
0.00271
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 9.8
nvd
почти 3 года назад

BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authenticity check for uploaded firmware. This can allow attackers to upload crafted firmware which contains backdoors and enables arbitrary code execution.

EPSS

Процентиль: 50%
0.00271
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-345