safakaslan/CelaLinkCLRM20

safakaslan/CelaLinkCLRM20

GitHubGitHub
Unavailable
This project is no longer available (or publicly accessible) from GitHub
Releases0
Arbitrary File Upload Cela Link CLR-M20

CVE History

CVEPublishedCVSS v3CVSS v2
10 HIGH

CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes remote code execution as well. Because of the WebDAV feature, it is possible to upload arbitrary files by utilizing the PUT method.