VYPR
Critical severity9.8NVD Advisory· Published Jun 13, 2023· Updated Nov 21, 2024

CVE-2023-3049

CVE-2023-3049

Description

Unrestricted file upload in TMT Lockcell allows unauthenticated remote command injection before version 15.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Unrestricted file upload in TMT Lockcell allows unauthenticated remote command injection before version 15.

Vulnerability

TMT Lockcell before version 15 contains an unrestricted file upload vulnerability that allows a dangerous file type to be uploaded, enabling command injection. The vulnerability exists in the file upload functionality accessible without authentication or prior privileges. Affected versions are Lockcell prior to 15. [1]

Exploitation

An unauthenticated attacker can send a crafted HTTP request to the Lockcell web interface, uploading a file containing malicious payload interpreted as a command. The attacker does not need any credentials or special network access beyond reachability of the web service. The vulnerable upload function accepts arbitrary file types without validation, leading to command execution on the server. [1]

Impact

Successful exploitation allows remote attackers to execute arbitrary commands on the underlying operating system with the privileges of the web server. This leads to full compromise of confidentiality, integrity, and availability of the affected device. [1]

Mitigation

TMT Lockcell released version 15 to fix the issue. Users should upgrade immediately to version 15 or later. No other workarounds are documented in the available references. [1]

AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • TMT/Lockcellllm-fuzzy2 versions
    <15+ 1 more
    • (no CPE)range: <15
    • (no CPE)range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.