CVE-2023-3049
Description
Unrestricted file upload in TMT Lockcell allows unauthenticated remote command injection before version 15.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Unrestricted file upload in TMT Lockcell allows unauthenticated remote command injection before version 15.
Vulnerability
TMT Lockcell before version 15 contains an unrestricted file upload vulnerability that allows a dangerous file type to be uploaded, enabling command injection. The vulnerability exists in the file upload functionality accessible without authentication or prior privileges. Affected versions are Lockcell prior to 15. [1]
Exploitation
An unauthenticated attacker can send a crafted HTTP request to the Lockcell web interface, uploading a file containing malicious payload interpreted as a command. The attacker does not need any credentials or special network access beyond reachability of the web service. The vulnerable upload function accepts arbitrary file types without validation, leading to command execution on the server. [1]
Impact
Successful exploitation allows remote attackers to execute arbitrary commands on the underlying operating system with the privileges of the web server. This leads to full compromise of confidentiality, integrity, and availability of the affected device. [1]
Mitigation
TMT Lockcell released version 15 to fix the issue. Users should upgrade immediately to version 15 or later. No other workarounds are documented in the available references. [1]
AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- fordefence.com/cve-2023-3049-unrestricted-upload-of-file-with-dangerous-type-vulnerability-allows-command-injection/nvdExploitThird Party Advisory
- www.usom.gov.tr/bildirim/tr-23-0345nvdThird Party Advisory
News mentions
0No linked articles in our index yet.