Home
CRITICAL: 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HDefault status
unaffected
0.0.0 (semver) before 6.0.1.0
affected
Default status
unaffected
0.0.0 (semver) before 6.0.1.0
affected
Default status
unaffected
0.0.0 (semver) before 6.0.1.0
affected
Description
Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupdate.cgi endpoint to upload and apply arbitrary updates.
Problem types
Product status
0.0.0 (semver) before 6.0.1.0
0.0.0 (semver) before 6.0.1.0
0.0.0 (semver) before 6.0.1.0
Credits
Adrien Rey from Cyber Defense Campus Zurich
Daniel Hulliger from Armasuisse
References
www.mbs-solutions.de/mbs-2025-0001