GHSA-873j-vp5v-78x9MediumCVSS 7.1
A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST...
🔗 CVE IDs covered (1)
📋 Description
A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lead to Denial-of-Service.