Arbitrary File Upload Vulnerability in ipTIME NAS Products by ipTIME
CVE-2020-7847
7.4HIGH
What is CVE-2020-7847?
The ipTIME NAS product has a vulnerability that allows for arbitrary file uploads via the Manage Bulletins/Upload feature. Attackers can exploit this flaw to upload malicious files, potentially leading to remote code execution. The affected version, ipTIME NAS 1.4.36, requires immediate attention to mitigate potential security risks that could compromise the system.
Affected Version(s)
ipTIME NAS 1.4.36
