Critical severity9.8NVD Advisory· Published Aug 31, 2020· Updated Jun 17, 2026
CVE-2020-7521
CVE-2020-7521
Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.0 and earlier) when accessing a vulnerable method of FileUploadServlet which may lead to uploading executable files to non-specified directories.
Affected products
2- cpe:2.3:o:schneider-electric:apc_easy_ups_online_software:*:*:*:*:*:*:*:*Range: <=2.0
- Range: <=V2.0
Patches
Vulnerability mechanics
References
1- www.se.com/ww/en/download/document/SEVD-2020-224-04/nvdVendor Advisory
News mentions
0No linked articles in our index yet.