VYPR
Critical severity9.8NVD Advisory· Published Aug 28, 2023· Updated Jun 17, 2026

CVE-2023-38029

CVE-2023-38029

Description

Saho’s attendance devices ADM100 and ADM-100FP has insufficient filtering for special characters and file type within their file uploading function. A unauthenticate remote attacker authenticated can upload and execute arbitrary files to perform arbitrary system commands or disrupt service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

15
  • cpe:2.3:o:saho:adm-100_firmware:0.0.4.0:*:*:*:*:*:*:*+ 7 more
    • cpe:2.3:o:saho:adm-100_firmware:0.0.4.0:*:*:*:*:*:*:*
    • cpe:2.3:o:saho:adm-100_firmware:0.0.4.3:*:*:*:*:*:*:*
    • cpe:2.3:o:saho:adm-100_firmware:0.0.4.6:*:*:*:*:*:*:*
    • cpe:2.3:o:saho:adm-100_firmware:0.0.4.8:*:*:*:*:*:*:*
    • cpe:2.3:o:saho:adm-100_firmware:q20100602:*:*:*:*:*:*:*
    • cpe:2.3:o:saho:adm-100_firmware:t17041702:*:*:*:*:*:*:*
    • cpe:2.3:o:saho:adm-100_firmware:t18051803:*:*:*:*:*:*:*
    • cpe:2.3:o:saho:adm-100_firmware:t190:*:*:*:*:*:*:*
  • cpe:2.3:o:saho:adm-100fp_firmware:q20100602:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:o:saho:adm-100fp_firmware:q20100602:*:*:*:*:*:*:*
    • cpe:2.3:o:saho:adm-100fp_firmware:t17041702:*:*:*:*:*:*:*
    • cpe:2.3:o:saho:adm-100fp_firmware:t18051803:*:*:*:*:*:*:*
    • cpe:2.3:o:saho:adm-100fp_firmware:t190:*:*:*:*:*:*:*
  • Saho/ADM100llm-fuzzy
  • Saho/Adm 100fpllm-fuzzy2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: Q20100602

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.