CVE-2024-0939

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 26, 2024
Updated: May 17, 2024
CWE ID 434

Summary

CVE-2024-0939 is a critical vulnerability affecting the Byzoro Smart S210 Management Platform up to version 20240117. The issue lies in the unknown code of the file /Tool/uploadfile.php, where the argument file_upload can be manipulated to permit unrestricted file uploads. This vulnerability can be exploited remotely, and the exploit has already been made public. The identifier for this vulnerability is VDB-252284, and despite early notification, the vendor has yet to respond. This cybersecurity flaw poses a significant risk and should be addressed promptly by affected organizations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share