Wertheim SafeController Software for VAULT ROOMS是Wertheim公司的一款金库安全保险柜系统的控制软件。 Wertheim SafeController Software for VAULT ROOMS 6.15.8328.28014版本存在任意文件上传漏洞,该漏洞源于/safe/contract/uploadcustomdocuments端点对服务器端文件类型验证不足,攻击者可通过伪造Content-Type值上传任意文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Wertheim GmbH | Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System) | Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Wertheim GmbH | Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System) | Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-34024 | Missing authorization checks in Wertheim SafeController Software allow low-privileged user | |
| CVE-2026-34028 | Unauthenticated direct access to web data in Wertheim SafeController Software exposes file | |
| CVE-2026-34022 | Weak custom cryptography and hard-coded keys in Wertheim SafeController 65000 allow traffi | |
| CVE-2026-34029 | Hard-coded cryptographic key in Wertheim SafeController Software allows decryption of sens | |
| CVE-2026-34025 | IP restriction bypass in Wertheim SafeController Software allows logins from unauthorized | |
| CVE-2026-34026 | Path traversal in Wertheim SafeController Software allows authenticated users to download | |
| CVE-2026-34021 | Lack of cryptographic protection in Wertheim SafeController 5400 enables RS-485 message sn | |
| CVE-2026-34030 | Improper branch-code validation in Wertheim SafeController Software allows file path manip | |
| CVE-2026-34023 | Broken WebSocket authorization in Wertheim SafeController Software allows cross-branch acc |
No comments yet