First published: Fri Mar 31 2023(Updated: )
There is an arbitrary file reading vulnerability in Generex UPS CS141 below 2.06 version. An attacker, making use of the default credentials, could upload a backup file containing a symlink to /etc/shadow, allowing him to obtain the content of this path.
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
Generex Cs141 Firmware | <2.06 | |
Generex CS141 |
This vulnerability, has been fixed by Generex team in CS141 version 2.12, released on December 2022.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-47188 is an arbitrary file reading vulnerability in Generex UPS CS141 below version 2.06.
CVE-2022-47188 has a severity score of 7.5 (high).
An attacker, using default credentials, can upload a backup file containing a symlink to /etc/shadow, allowing them to obtain the content of this path.
Generex CS141 firmware below version 2.06 is affected by CVE-2022-47188.
Update the Generex UPS CS141 firmware to version 2.06 or above to mitigate CVE-2022-47188.