A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lead to Denial-of-Service.
References
| Link | Resource |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-008/ |
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-30 07:16
Updated : 2026-07-30 16:17
NVD link : CVE-2026-44097
Mitre link : CVE-2026-44097
CVE.ORG link : CVE-2026-44097
JSON object : View
Products Affected
No product.
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
