There is an arbitrary file reading vulnerability in Generex UPS CS141 below 2.06 version. An attacker, making use of the default credentials, could upload a backup file containing a symlink to /etc/shadow, allowing him to obtain the content of this path.
2023-03-31T22:15:07.227
2024-11-21T07:31:40.420
Modified
CVSSv3.1: 7.5 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | generex | cs141_firmware | < 2.06 | Yes |
| Hardware | generex | cs141 | - | No |