Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-88738

Опубликовано: 21 сент. 2026
Источник: nvd
EPSS Низкий

Описание

Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An authenticated attacker can upload a server-side executable file. The uploaded file is stored in a web-accessible executable location and can be accessed directly over HTTP without authentication, resulting in remote code execution.

EPSS

Процентиль: 16%
0.00241
Низкий

Дефекты

Связанные уязвимости

CVSS3: 8.8
github
2 дня назад

Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An authenticated attacker can upload a server-side executable file. The uploaded file is stored in a web-accessible executable location and can be accessed directly over HTTP without authentication, resulting in remote code execution.

EPSS

Процентиль: 16%
0.00241
Низкий

Дефекты