Impact
A POST request to a specific webserver endpoint accepts a filename parameter via the Content-Disposition header without verification, allowing an attacker to overwrite arbitrary files. This flaw, mapped to CWE-20, can be leveraged to overwrite system files or shell scripts, potentially causing denial of service or enabling remote code execution if the overwritten scripts are later executed. The impact involves loss of data integrity and availability; no confidentiality impact is described.
Affected Systems
The vulnerability affects the EVbee DC-80 device. Because the vendor does not provide a specific vulnerable version range, all deployed instances of EVbee DC-80 should be considered vulnerable until a vendor‑issued fix is released.
Risk and Exploitability
The flaw is scored at 9.3 on the CVSS scale, indicating critical severity. An EPSS score below 1% suggests a low but non‑zero likelihood of exploitation today. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely a web‑based POST request to the certificate‑update endpoint, and the description does not mention authentication requirements, implying that any host able to reach the endpoint could exploit the flaw. Due to the high severity, timely remediation is essential.
OpenCVE Enrichment