Home
HIGH: 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
0.0.0 (semver) before 6.0.1.0
affected
Default status
unaffected
0.0.0 (semver) before 6.0.1.0
affected
Default status
unaffected
0.0.0 (semver) before 6.0.1.0
affected
Description
A low-privileged remote attacker can exploit an arbitrary file write vulnerability in the wwupload.cgi endpoint. Due to path traversal this can lead to overwriting arbitrary files on the device and achieving a full system compromise.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
0.0.0 (semver) before 6.0.1.0
0.0.0 (semver) before 6.0.1.0
0.0.0 (semver) before 6.0.1.0
Credits
Adrien Rey from Cyber Defense Campus Zurich
Daniel Hulliger from Armasuisse
References
www.mbs-solutions.de/mbs-2025-0001