Vulnerability Description
CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes remote code execution as well. Because of the WebDAV feature, it is possible to upload arbitrary files by utilizing the PUT method.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cela Link | Clr-M20 Firmware | 2.7.1.6 |
| Cela Link | Clr-M20 | - |
Related Weaknesses (CWE)
References
- https://github.com/safakaslan/CelaLinkCLRM20/issues/1Third Party Advisory
- https://www.exploit-db.com/exploits/45021/Third Party AdvisoryVDB Entry
- https://github.com/safakaslan/CelaLinkCLRM20/issues/1Third Party Advisory
- https://www.exploit-db.com/exploits/45021/Third Party AdvisoryVDB Entry
FAQ
What is CVE-2018-15137?
CVE-2018-15137 is a vulnerability with a CVSS score of 9.8 (CRITICAL). CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes remote code execution as well. Because of the WebDAV feature, it ...
How severe is CVE-2018-15137?
CVE-2018-15137 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-15137?
Check the references section above for vendor advisories and patch information. Affected products include: Cela Link Clr-M20 Firmware, Cela Link Clr-M20.