rootpwn

high · CVSS v3 8.8

CVE-2026-88738

Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload fu…

Description

Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An authenticated attacker can upload a server-side executable file. The uploaded file is stored in a web-accessible executable location and can be accessed directly over HTTP without authentication, resulting in remote code execution.

Scores

Severity
high
CVSS v2
6.5
CVSS v3
8.8
CVSS v4
EPSS

← All CVEs