VulnerabilityModified
CVE-2018-15137
CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes remote code execution as well.
CRITICAL 9.8EPSS 18.2%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 18.2%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes remote code execution as well. Because of the WebDAV feature, it is possible to upload arbitrary files by utilizing the PUT method.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 18.20% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- cela link/clr-m20 firmware
- Source
- cve@mitre.org
References
- https://github.com/safakaslan/CelaLinkCLRM20/issues/1Third Party Advisory
- https://www.exploit-db.com/exploits/45021/Third Party Advisory, VDB Entry
- https://github.com/safakaslan/CelaLinkCLRM20/issues/1Third Party Advisory
- https://www.exploit-db.com/exploits/45021/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.