漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Authenticated Arbitrary Python File Upload via Plugin Manager
Vulnerability Description
An authenticated attacker is able to use the Plugin Manager of the web interface of the Wattsense Bridge devices to upload malicious Python files to the device. This enables an attacker to gain remote root access to the device. An attacker needs a valid user account on the Wattsense web interface to be able to conduct this attack. This issue is fixed in recent firmware versions BSP >= 6.1.0.
CVSS Information
N/A
Vulnerability Type
危险类型文件的不加限制上传
Vulnerability Title
Wattsense Bridge 安全漏洞
Vulnerability Description
Wattsense Bridge是Wattsense公司的一款直观且功能强大的物联网网关。 Wattsense Bridge存在安全漏洞。攻击者利用该漏洞可以获得设备的远程 root 访问权限。
CVSS Information
N/A
Vulnerability Type
N/A