CVE-2026-88738
Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-434
Subida sin restricciones de ficheros de tipos peligrosos
Fecha de publicación:
21/09/2026
Última modificación:
22/09/2026
Descripción
*** Pendiente de traducción *** Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An attacker with administrative privileges can upload a server-side executable file. The uploaded file is stored in a web-accessible executable location and can be accessed directly over HTTP without authentication, resulting in remote code execution.
Impacto
Puntuación base 3.x
8.80
Gravedad 3.x
ALTA
Referencias a soluciones, herramientas e información
- https://lcybersec.notion.site/CVE-2026-88738-Unrestricted-file-upload-vulnerability-resulting-in-remote-code-execution-in-Jazzwa-3e06e8f484b5809e9eb3ffa705995d22
- https://lcybersec.notion.site/CVE-2026-88738-Unrestricted-file-upload-vulnerability-resulting-in-remote-code-execution-in-Jazzwa-3e06e8f484b5809e9eb3ffa705995d22


