Description
A flaw has been found in ShuoRen Smart Heating Integrated Management Platform 1.0.0. Affected by this vulnerability is an unknown functionality of the file /MP/Service/Webservice/ExampleNodeService.asmx. Executing a manipulation of the argument File can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Problem types
Product status
Timeline
| 2026-02-23: | Advisory disclosed |
| 2026-02-23: | VulDB entry created |
| 2026-02-23: | VulDB entry last update |
Credits
zsmaaa (VulDB User)
References
vuldb.com/?id.347381 (VDB-347381 | ShuoRen Smart Heating Integrated Management Platform ExampleNodeService.asmx unrestricted upload)
vuldb.com/?ctiid.347381 (VDB-347381 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.756376 (Submit #756376 | 北京硕人时代科技股份有限公司 北京硕人时代智慧供热平台 1.0.0 未登录下文件上传以及下载)