PT-2026-96811 · Slb882+6 · Slb882+6
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SLC8000 versions prior to 9.7.0.5
SLC9000 versions prior to 9.7.0.2
EMG8500/EMG7500 versions prior to 9.7.0.1
SLB882 (affected versions not specified)
SLCx-03 (affected versions not specified)
SLCx-02 (affected versions not specified)
Description
A path traversal issue exists in the web management portal upload endpoint. This occurs because the filename validation process removes backslash characters but fails to check for forward slashes when a backslash is identified. An authenticated attacker can exploit this by providing a filename containing both characters to write arbitrary data to any writable location on the device filesystem, which can lead to remote code execution. This may result in a complete loss of confidentiality, integrity, and availability of the device and potentially affect downstream serial-connected devices.
Recommendations
Update SLC8000 to firmware version 9.7.0.5 or later.
Update SLC9000 to firmware version 9.7.0.2 or later.
Update EMG8500/EMG7500 to firmware version 9.7.0.1 or later.
At the moment, there is no information about a newer version that contains a fix for this vulnerability for SLB882, SLCx-03, and SLCx-02.
Fix
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emg7500
Emg8500
Slb882
Sc8000
Slc9000
Slcx-02
Slcx-03