Web Viewer 1.0.0.193 on Samsung SRN-1670D devices suffers from an Unrestricted file upload vulnerability: 'network_ssl_upload.php' allows remote authenticated attackers to upload and execute arbitrary PHP code via a filename with a .php extension, which is then accessed via a direct request to the file in the upload/ directory. To authenticate for this attack, one can obtain web-interface credentials in cleartext by leveraging the existing Local File Read Vulnerability referenced as CVE-2015-8279, which allows remote attackers to read the web-interface credentials via a request for the cslog_export.php?path=/root/php_modules/lighttpd/sbin/userpw URI.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T20:27:03.694Z

Reserved: 2017-11-03T00:00:00

Link: CVE-2017-16524

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-11-06T08:29:00.220

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-16524

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses