Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-10478

Опубликовано: 05 апр. 2019
Источник: nvd
CVSS3: 7.2
CVSS2: 9
EPSS Низкий

Описание

An issue was discovered on Glory RBW-100 devices with firmware ISP-K05-02 7.0.0. An unrestricted file upload vulnerability in the Front Circle Controller glytoolcgi/settingfile_upload.cgi allows attackers to upload supplied data. This can be used to place attacker controlled code on the filesystem that can be executed and can lead to a reverse root shell.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:glory-global:rbw-100_firmware:isp-k05-02_7.0.0:*:*:*:*:*:*:*
cpe:2.3:h:glory-global:rbw-100:-:*:*:*:*:*:*:*

EPSS

Процентиль: 72%
0.00726
Низкий

7.2 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.2
github
больше 3 лет назад

An issue was discovered on Glory RBW-100 devices with firmware ISP-K05-02 7.0.0. An unrestricted file upload vulnerability in the Front Circle Controller glytoolcgi/settingfile_upload.cgi allows attackers to upload supplied data. This can be used to place attacker controlled code on the filesystem that can be executed and can lead to a reverse root shell.

EPSS

Процентиль: 72%
0.00726
Низкий

7.2 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-434