VYPR

Nexo Cordless Nutrunner Nxa015s 36v B (0608842006)

by Rexroth

CVEs (25)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2023-482460.000.00Jan 10, 2024The vulnerability allows a remote attacker to download arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.
CVE-2023-482450.000.00Jan 10, 2024The vulnerability allows an unauthenticated remote attacker to upload arbitrary files under the context of the application OS user (“root”) via a crafted HTTP request.
CVE-2023-482440.000.00Jan 10, 2024The vulnerability allows a remote attacker to inject and execute arbitrary client-side script code inside a victim’s session via a crafted URL or HTTP request.
CVE-2023-482430.000.02Jan 10, 2024The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request. By abusing this vulnerability, it is possible to obtain remote code execution (RCE) with root privileges on the device.
CVE-2023-482420.000.00Jan 10, 2024The vulnerability allows an authenticated remote attacker to download arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.

Page 2 of 2