SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecified vectors. If the file is PHP script, an attacker may execute arbitrary code.
References
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2021-02-24 04:15
Updated : 2021-03-01 08:09
NVD link : CVE-2021-20659
Mitre link : CVE-2021-20659
JSON object : View
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
Products Affected
contec
- sv-cpt-mc310
- sv-cpt-mc310_firmware