Back

HIGH

The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request

Published Jan 10, 2024

Description

The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request. By abusing this vulnerability, it is possible to obtain remote code execution (RCE) with root privileges on the device.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner bosch
Published Jan 10, 2024
Updated Jun 17, 2025
Reserved Nov 13, 2023

CISA Vulnrichment

Updated Jan 10, 2024

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner bosch
Published Jan 10, 2024
Updated Jun 17, 2025

GitHub

No data