CVE-2021-20659: Malicious File Upload
SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecified vectors. If the file is PHP script, an attacker may execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-20659?
CVE-2021-20659 is categorized as a medium severity vulnerability due to the potential for authenticated attackers to execute arbitrary code.
How do I fix CVE-2021-20659?
To mitigate CVE-2021-20659, upgrade the SolarView Compact SV-CPT-MC310 firmware to version 6.5 or later.
What type of files can be uploaded in CVE-2021-20659?
In CVE-2021-20659, an attacker can upload arbitrary files, including PHP scripts, that can be executed.
Is authentication required to exploit CVE-2021-20659?
Yes, exploiting CVE-2021-20659 requires authentication to the SolarView Compact SV-CPT-MC310.
What are the potential consequences of CVE-2021-20659?
The consequences of CVE-2021-20659 include unauthorized remote code execution, which could compromise the integrity of the system.