Impact
A flaw in refirio’s freo2 lets an attacker who holds the highest level of administrative privileges upload a file of any type, including executable binaries. The application then executes the uploaded file’s contents as an operating‑system command, granting the attacker full control over the server.
Affected Systems
The vulnerable product is freo2 from refirio. No specific version is listed, so all current or future releases are potentially affected until a vendor update is applied.
Risk and Exploitability
The CVSS score of 8.6 denotes a high‑severity issue. Because the attack requires local administrative access, the likelihood of an outsider exploiting it is low, but an insider or compromised administrator can abuse the flaw immediately. The EPSS score is not reported and the vulnerability is not in the CISA KEV catalog, indicating no known active exploitation at present.
OpenCVE Enrichment