GHSA-873j-vp5v-78x9MediumCVSS 7.1

A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST...

Published
July 30, 2026
Last Modified
July 30, 2026

🔗 CVE IDs covered (1)

📋 Description

A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lead to Denial-of-Service.

🔗 References (3)