CVE-2026-88738
Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An attacker with administrative privileges can upload a server-side executable file. The uploaded file is stored in a web-accessible executable location and can be accessed directly over HTTP without authentication, resulting in remote code execution.
Słabość
Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An attacker with administrative privileges can upload a server-side executable file. The uploaded file is stored in a web-accessible executable location and can be accessed directly over HTTP without authentication, resulting in remote code execution.
Źródła
- https://lcybersec.notion.site/CVE-2026-88738-Unrestricted-file-upload-vulnerability-resulting-in-remote-code-execution-in-Jazzwa-3e06e8f484b5809e9eb3ffa705995d22
- https://lcybersec.notion.site/CVE-2026-88738-Unrestricted-file-upload-vulnerability-resulting-in-remote-code-execution-in-Jazzwa-3e06e8f484b5809e9eb3ffa705995d22
Znajdź błąd, zanim zrobi to atakujący.
Zaloguj się przez GitHub i uruchom pierwszy audyt w niecałą minutę. Plan darmowy nie wymaga karty kredytowej.