CVE-2026-88738: Jazzware RT1000 Edge webUI vulnerability
Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An authenticated attacker can upload a server-side executable file. The uploaded file is stored in a web-accessible executable location and can be accessed directly over HTTP without authentication, resulting in remote code execution.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
An attacker must be authenticated to use the upgrade package upload functionality. After uploading a server-side executable file, the attacker can access it directly over HTTP without authentication.
Does exploitation require a separate authenticated request to execute the uploaded file?
No. The uploaded executable is stored in a web-accessible location and can be invoked directly over HTTP without authentication after upload.
What is the potential impact of a successful exploit?
A successful attacker can achieve remote code execution by uploading a server-side executable file through the upgrade package upload feature.