Impact
An unrestricted file upload flaw in the upgrade package upload function of Jazzware RT1000 Edge webUI enables an attacker who has valid credentials to place any server‑side executable on the device. The uploaded file is written to an area that is reachable via HTTP without requiring authentication, allowing the attacker to execute arbitrary code on the underlying system. This compromise can lead to full control over the device, including data theft, modification, or service disruption.
Affected Systems
The affected product is Jazzware RT1000 Edge webUI version 20.0.1. No other vendors or product versions are mentioned in the data.
Risk and Exploitability
The vulnerability provides remote code execution after authentication and without further authentication for file access, indicating a high likelihood of exploitation. The CVSS score is not provided in the data, and the EPSS score is unavailable, but the nature of the flaw suggests a severe risk. The vulnerability is not listed in the CISA KEV catalog as of this analysis.
OpenCVE Enrichment