peter bassill · operator
$ cve CVE-2018-15137 JSON

CVE-2018-15137 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 18.2% (pctl 97)

Patch early

A public exploit exists.

Description

CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes remote code execution as well. Because of the WebDAV feature, it is possible to upload arbitrary files by utilizing the PUT method.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS18.2% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploityes
Published2018-08-08
Last modified2026-06-17

Affected (2)

VendorProduct
cela linkclr-m20
cela linkclr-m20 firmware

Public exploits

SourceTitleDate
exploit-dbCela Link CLR-M20 2.7.1.6 - Arbitrary File Upload2018-07-13

References

→ the Explorer  ·  watch your stack  ·  NVD