Arbitrary .php File Upload Vulnerability in Socomec REMOTE VIEW PRO 2.0.41.4

Arbitrary .php File Upload Vulnerability in Socomec REMOTE VIEW PRO 2.0.41.4

CVE-2021-41870 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

An issue was discovered in the firmware update form in Socomec REMOTE VIEW PRO 2.0.41.4. An authenticated attacker can bypass a client-side file-type check and upload arbitrary .php files.

Learn more about our Web Application Penetration Testing UK.