Vulnerability Description
An issue was discovered on Glory RBW-100 devices with firmware ISP-K05-02 7.0.0. An unrestricted file upload vulnerability in the Front Circle Controller glytoolcgi/settingfile_upload.cgi allows attackers to upload supplied data. This can be used to place attacker controlled code on the filesystem that can be executed and can lead to a reverse root shell.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Glory-Global | Rbw-100 Firmware | isp-k05-02_7.0.0 |
| Glory-Global | Rbw-100 | - |
Related Weaknesses (CWE)
References
- https://github.com/warringaa/CVEs#glory-systems-rbw-100ExploitThird Party Advisory
- https://github.com/warringaa/CVEs#glory-systems-rbw-100ExploitThird Party Advisory
FAQ
What is CVE-2019-10478?
CVE-2019-10478 is a vulnerability with a CVSS score of 7.2 (HIGH). An issue was discovered on Glory RBW-100 devices with firmware ISP-K05-02 7.0.0. An unrestricted file upload vulnerability in the Front Circle Controller glytoolcgi/settingfile_upload.cgi allows attac...
How severe is CVE-2019-10478?
CVE-2019-10478 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-10478?
Check the references section above for vendor advisories and patch information. Affected products include: Glory-Global Rbw-100 Firmware, Glory-Global Rbw-100.