LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2017-20224

telesquare · sdt-cs3b1 firmware

Published
CVSS9.8
Severitycritical
WeaknessCWE-434
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious content by exploiting enabled WebDAV HTTP methods. Attackers can use PUT, DELETE, MKCOL, MOVE, COPY, and PROPPATCH methods to upload executable code, delete files, or manipulate server content for remote code execution or denial of service.

References

← Back to the CVE Tracker

Our coverage of CVE-2017-20224

No stories yet. This page updates automatically when we publish reporting that references CVE-2017-20224.