HGiga OAKlouds file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary command or disrupt service.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-29797 | HGiga OAKlouds file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary command or disrupt service. |
Fixes
Solution
- Update OAKlouds-layout-2.0 to OAKlouds-layout-2.0-10 - Update OAKlouds-layout-3.0 to OAKlouds-layout-3.0-10
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-6973-45872-1.html |
|
History
Wed, 19 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-02-19T15:46:34.848Z
Reserved: 2023-02-16T00:00:00.000Z
Link: CVE-2023-25909
Updated: 2024-08-02T11:32:12.744Z
Status : Modified
Published: 2023-03-27T04:15:10.473
Modified: 2024-11-21T07:50:24.600
Link: CVE-2023-25909
No data.
OpenCVE Enrichment
No data.
EUVD