Impact
A high‑privileged remote attacker can upload a .php file and then request it from /uploads/<filename>.php, achieving arbitrary code execution because the application performs insufficient file type validation. The vulnerability can lead to full system compromise and is classified as a file upload flaw under CWE-434.
Affected Systems
Frauscher Sensortechnik’s FDS 102 sensor platform (R2 version) is affected. No specific software version numbers are listed; all installations of the FDS 102 that allow direct uploads to the /uploads directory are vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.6, indicating a high‑risk flaw. EPSS is below 1%, so the exploitation probability is low but not negligible, and the flaw is not listed in the CISA KEV catalog. A remote attacker who can reach the upload endpoint and place a malicious file in the uploads directory can immediately execute it to gain code‑execution privileges, without needing additional authentication or privilege escalation.
OpenCVE Enrichment