First published: Tue Aug 16 2022(Updated: )
The image file management page of SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and earlier contains an insufficient verification vulnerability when uploading files. If this vulnerability is exploited, arbitrary PHP code may be executed if a remote authenticated attacker uploads a specially crafted PHP file.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Contec Sv-cpt-mc310f Firmware | <7.24 | |
Contec Sv-cpt-mc310f | ||
Contec Sv-cpt-mc310 Firmware | <7.24 | |
Contec Sv-cpt-mc310 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-35239.
The severity of CVE-2022-35239 is high (8.8).
The affected software is SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and earlier.
The vulnerability in the affected software is an insufficient verification vulnerability when uploading files, which may allow execution of arbitrary PHP code.
Refer to the official references provided for mitigation steps and firmware updates.