Impact
The vulnerability is a path traversal flaw in the server import and admin file upload features of Crafty Controller, allowing a remote authenticated attacker to upload files to arbitrary paths that the application is permitted to write. By uploading malicious code to such locations, an attacker can achieve remote code execution. The weakness corresponds to CWE-35, representing path traversal.
Affected Systems
Arcadia Technology, LLC publishes Crafty Controller. No explicit version range is supplied; all releases before 4.10.8 are potentially impacted according to the vendor's advisory. Administrators should verify whether their environment is using an earlier version.
Risk and Exploitability
The flaw carries a CVSS score of 9.1, indicating severe risk. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation yet. The attack vector requires authenticated access, but the ability to upload code grants attackers the power to execute arbitrary code on the underlying host, posing a system‑wide compromise risk. The high severity and potential for remote code execution warrant urgent action.
OpenCVE Enrichment