CyberRota Analysis
AI-GeneratedThe Jazzware RT1000 Edge webUI version 20.0.1 is vulnerable due to an unrestricted file upload feature that allows authenticated attackers to upload executable files. These files are stored in a publicly accessible location, enabling remote code execution without further authentication. Organizations using this version should prioritize addressing this vulnerability to mitigate the risk of unauthorized access and potential system compromise.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An attacker with administrative privileges can upload a server-side executable file. The uploaded file is stored in a web-accessible executable location and can be accessed directly over HTTP without authentication, resulting in remote code execution.