CVE-2018-15137 EXPLOIT
9.8
CRITICAL · CVSS 3.0 · EPSS 18.2% (pctl 97)
Patch early
A public exploit exists.
Description
CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes remote code execution as well. Because of the WebDAV feature, it is possible to upload arbitrary files by utilizing the PUT method.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 18.2% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-434 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-08-08 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| cela link | clr-m20 |
| cela link | clr-m20 firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Cela Link CLR-M20 2.7.1.6 - Arbitrary File Upload | 2018-07-13 |
References
→ the Explorer · watch your stack · NVD