Critical severity9.8NVD Advisory· Published Nov 22, 2017· Updated May 13, 2026
CVE-2017-8862
CVE-2017-8862
Description
The webupgrade function on the Cohu 3960HD does not verify the firmware upgrade files or process, allowing an attacker to upload a specially crafted postinstall.sh file that will be executed with "root" privileges.
Affected products
1- cpe:2.3:o:cohuhd:3960hd_firmware:-:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- bneg.io/2017/05/12/vulnerabilities-in-cohu-3960hd/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.