First published: Fri Mar 31 2023(Updated: )
Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a webshell that could allow him to execute arbitrary code as root.
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
Generex Cs141 Firmware | <2.06 | |
Generex CS141 |
This vulnerability, has been fixed by Generex team in CS141 version 2.12, released on December 2022.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-47190 is a vulnerability in Generex UPS CS141 below version 2.06 that allows a remote attacker to upload a firmware file containing a webshell, enabling them to execute arbitrary code as root.
Generex UPS CS141 below version 2.06 is affected by CVE-2022-47190.
The severity of CVE-2022-47190 is rated as critical with a CVSS score of 9.8.
An attacker can exploit CVE-2022-47190 by uploading a firmware file containing a webshell, which allows them to execute arbitrary code as root.
To mitigate CVE-2022-47190, it is recommended to update Generex UPS CS141 to version 2.06 or higher, as this vulnerability has been addressed in the latest version.