CVE-2023-3049
Severity CVSS v4.0:
Pending analysis
Type:
CWE-434
Unrestricted Upload of File with Dangerous Type
Publication date:
13/06/2023
Last modified:
22/05/2026
Description
Unrestricted Upload of File with Dangerous Type vulnerability in TMT Lockcell allows Command Injection.<br />
<br />
This issue affects Lockcell: before 15.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:tmtmakine:lockcell_firmware:*:*:*:*:*:*:*:* | 15.0 (excluding) | |
| cpe:2.3:h:tmtmakine:lockcell:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://fordefence.com/cve-2023-3049-unrestricted-upload-of-file-with-dangerous-type-vulnerability-allows-command-injection/
- https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-23-0345
- https://www.usom.gov.tr/bildirim/tr-23-0345
- https://fordefence.com/cve-2023-3049-unrestricted-upload-of-file-with-dangerous-type-vulnerability-allows-command-injection/
- https://www.usom.gov.tr/bildirim/tr-23-0345



