Описание
An issue in upload.csp of FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows attackers to write files and reset the user passwords without having a valid session cookie.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:o:fantec:mwid25-ds_firmware:2.000.030:*:*:*:*:*:*:*
cpe:2.3:h:fantec:mwid25-ds:-:*:*:*:*:*:*:*
EPSS
Процентиль: 92%
0.08782
Низкий
7.2 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-565
Связанные уязвимости
CVSS3: 7.2
github
почти 4 года назад
An issue in upload.csp of FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows attackers to write files and reset the user passwords without having a valid session cookie.
EPSS
Процентиль: 92%
0.08782
Низкий
7.2 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-565