|CVSS SCORE||9.8, (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Advantech WISE-PaaS/RMM. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the DeviceMapMgmt class. When parsing the LastMapName, the process does not properly validate a user-supplied path prior to using it in file operations.
Advantech has issued an update to correct this vulnerability. More details can be found at:
|CREDIT||rgod of 9sg