Show filters
25 Total Results
Displaying 21-25 of 25
Sort by:
Attacker Value
Unknown
CVE-2023-48246
Disclosure Date: January 10, 2024 (last updated January 17, 2024)
The vulnerability allows a remote attacker to download arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.
0
Attacker Value
Unknown
CVE-2023-48245
Disclosure Date: January 10, 2024 (last updated January 17, 2024)
The vulnerability allows an unauthenticated remote attacker to upload arbitrary files under the context of the application OS user (“root”) via a crafted HTTP request.
0
Attacker Value
Unknown
CVE-2023-48244
Disclosure Date: January 10, 2024 (last updated January 17, 2024)
The vulnerability allows a remote attacker to inject and execute arbitrary client-side script code inside a victim’s session via a crafted URL or HTTP request.
0
Attacker Value
Unknown
CVE-2023-48243
Disclosure Date: January 10, 2024 (last updated January 17, 2024)
The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.
By abusing this vulnerability, it is possible to obtain remote code execution (RCE) with root privileges on the device.
0
Attacker Value
Unknown
CVE-2023-48242
Disclosure Date: January 10, 2024 (last updated January 17, 2024)
The vulnerability allows an authenticated remote attacker to download arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.
0