PT-2026-24028 · Unknown · Wwupload.Cgi

Adrien Rey

+1

·

Published

2026-03-09

·

Updated

2026-03-12

·

CVE-2025-41758

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Versions (affected versions not specified)
Description A low-privileged remote attacker can exploit an arbitrary file write vulnerability in the wwupload.cgi API endpoint. This is due to path traversal, which can lead to overwriting arbitrary files on the device and achieving a full system compromise.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-41758

Affected Products

Wwupload.Cgi