github.com
https://github.com/safakaslan/CelaLinkCLRM20/issues/1 CVE-2018-15137
CRITICAL
Cela Link CLR-M20 2.7.1.6 - Arbitrary File Upload
Record summary
CVE-2018-15137 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes remote code execution as well. Because of the WebDAV feature, it is possible to upload arbitrary files by utilizing the PUT method.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCela Link CLR-M20 2.7.1.6 - Arbitrary File UploadExploitDB exploitby Safak AslanNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-15137 45021exploit
https://www.exploit-db.com/exploits/45021