Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-50625


An issue was discovered in Digi ConnectPort LTS before 1.4.12. A vulnerability in the file upload handling of a web application allows manipulation of file paths via POST requests. This can lead to arbitrary file uploads within specific directories, potentially enabling privilege escalation when combined with other vulnerabilities.


Published

2024-12-09T22:15:22.610

Last Modified

2025-06-27T16:07:48.380

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.0 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-434

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System digi connectport_lts_firmware < 1.4.12 Yes
Hardware digi connectport_lts_16 - No
Hardware digi connectport_lts_16_mei - No
Hardware digi connectport_lts_16_mei_2ac - No
Hardware digi connectport_lts_32 - No
Hardware digi connectport_lts_32_mei - No
Hardware digi connectport_lts_8_mei - No

References