ZeroHour

CVE-2021-26915

PoC ×2
CVSS 3.1
8.1 high
EPSS
42%p99
Published
()
Modified
Description

NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in webrepdb StatusServlet.

Vendors
netmotionsoftware
Products
netmotion mobility
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.