CVE-2022-36557

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
29/08/2022
Last modified:
02/09/2022

Description

Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the restore backup function. This vulnerability allows attackers to execute arbitrary code via a crafted html file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:seiko-sol:skybridge_mb-a100_firmware:*:*:*:*:*:*:*:* 4.2.0 (including)
cpe:2.3:h:seiko-sol:skybridge_mb-a100:-:*:*:*:*:*:*:*
cpe:2.3:o:seiko-sol:skybridge_mb-a110_firmware:*:*:*:*:*:*:*:* 4.2.0 (including)
cpe:2.3:h:seiko-sol:skybridge_mb-a110:-:*:*:*:*:*:*:*