A low privileged remote attacker can upload arbitrary data masked as a png file to the affected device using the webserver API because only the file extension is verified.
Metrics
Affected Vendors & Products
References
History
Wed, 22 Oct 2025 07:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A low privileged remote attacker can upload arbitrary data masked as a png file to the affected device using the webserver API because only the file extension is verified. | |
Title | Sauter: Arbitrary File Upload | |
Weaknesses | CWE-646 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2025-10-22T06:52:03.019Z
Reserved: 2025-04-16T11:17:48.313Z
Link: CVE-2025-41720

No data.

Status : Received
Published: 2025-10-22T07:15:33.317
Modified: 2025-10-22T07:15:33.317
Link: CVE-2025-41720

No data.

No data.