ZeroHour

CVE-2023-27748

PoC ×2
CVSS 3.1
9.8 critical
EPSS
<1%p52
Published
()
Modified
Description

BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authenticity check for uploaded firmware. This can allow attackers to upload crafted firmware which contains backdoors and enables arbitrary code execution.

Vendors
blackvue
Products
dr750-2ch lte firmware, dr750-2ch ir lte firmware
Weakness
CWE-345
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.