CVE-2023-3049
9.8
CRITICAL · CVSS 3.1 · EPSS 3.7% (pctl 90)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Unrestricted Upload of File with Dangerous Type vulnerability in TMT Lockcell allows Command Injection. This issue affects Lockcell: before 15.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.74% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-434 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2023-06-13 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| tmtmakine | lockcell |
| tmtmakine | lockcell firmware |
References
- https://fordefence.com/cve-2023-3049-unrestricted-upload-of-file-with-dangerous-type-vulnerability-allows-command-injection/
- https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-23-0345
- https://www.usom.gov.tr/bildirim/tr-23-0345
- https://fordefence.com/cve-2023-3049-unrestricted-upload-of-file-with-dangerous-type-vulnerability-allows-command-injection/
- https://www.usom.gov.tr/bildirim/tr-23-0345
→ the Explorer · watch your stack · NVD