Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h2j2-qx54-6hmh

Опубликовано: 29 янв. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. The UpgradePrepare is the API that checks if a provided filename identifies a new version of the RLC-410W firmware. If the version is new, it would be possible, allegedly, to later on perform the Upgrade. An attacker can send an HTTP request to trigger this vulnerability.

An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. The UpgradePrepare is the API that checks if a provided filename identifies a new version of the RLC-410W firmware. If the version is new, it would be possible, allegedly, to later on perform the Upgrade. An attacker can send an HTTP request to trigger this vulnerability.

EPSS

Процентиль: 43%
0.00207
Низкий

8.8 High

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 7.1
nvd
около 4 лет назад

An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. The UpgradePrepare is the API that checks if a provided filename identifies a new version of the RLC-410W firmware. If the version is new, it would be possible, allegedly, to later on perform the Upgrade. An attacker can send an HTTP request to trigger this vulnerability.

EPSS

Процентиль: 43%
0.00207
Низкий

8.8 High

CVSS3

Дефекты

CWE-276