Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-15137

CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes remote code execution as well. Because of the WebDAV feature, it is possible to upload arbitrary files by utilizing the PUT method.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.262
EPSS Ranking 96.0%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 10.0
Products affected by CVE-2018-15137


Contact Us

Shodan ® - All rights reserved