A CWE-646 “Reliance on File Name or Extension of...
Moderate severity
Unreviewed
Published
Mar 5, 2024
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Mar 5, 2024
Published to the GitHub Advisory Database
Mar 5, 2024
A CWE-646 “Reliance on File Name or Extension of Externally-Supplied File” vulnerability in the “iec61850” functionality of the web application allows a remote authenticated attacker to upload any arbitrary type of file into the device. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.
References