PT-2023-11483 · Uffizio · Uffizio'S Gps Tracker
Published
2023-12-16
·
Updated
2023-12-20
·
CVE-2020-17485
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Uffizio's GPS Tracker all versions
Description
A Remote Code Execution issue exists, allowing the web server to be compromised by uploading and executing a web/reverse shell. This enables an attacker to run commands, browse system files, and access local resources.
Recommendations
For all versions, consider disabling the web server functionality or restricting access to it until a fix is available. As a temporary workaround, restrict the ability to upload files to the web server to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Uffizio'S Gps Tracker