SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arbitrary files and execute OS commands with SYSTEM privileges.
References
Configurations
No configuration.
History
28 Aug 2025, 09:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-28 09:15
Updated : 2025-08-29 16:24
NVD link : CVE-2025-54762
Mitre link : CVE-2025-54762
CVE.ORG link : CVE-2025-54762
JSON object : View
Products Affected
No product.
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type