The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.
By abusing this vulnerability, it is possible to obtain remote code execution (RCE) with root privileges on the device.
CVSS
No CVSS.
References
Configurations
No configuration.
Information
Published : 2024-01-10 11:15
Updated : 2024-01-10 13:56
NVD link : CVE-2023-48243
Mitre link : CVE-2023-48243
JSON object : View
Products Affected
No product.
CWE
No CWE.
