ZeroHour

CVE-2021-38611

PoC
CVSS 3.1
9.8 critical
EPSS
2%p79
Published
()
Modified
Description

A command-injection vulnerability in the Image Upload function of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to execute arbitrary commands, as root, via shell metacharacters in the filename parameter to assets/index.php.

Vendors
nascent
Products
remkon device manager
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.