VYPR
Critical severity9.8CISA KEVNVD Advisory· Published Sep 13, 2021· Updated Jun 17, 2026

CVE-2021-40870

CVE-2021-40870

Description

An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:aviatrix:controller:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:aviatrix:controller:*:*:*:*:*:*:*:*range: >=6.2,<6.2.2043
    • (no CPE)range: <6.5-1804.1922
  • Aviatrix/Aviatrix Controllerdescription

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.