CVE-2021-26625

HIGH

Nexacro 17.0.0-17.1.3.700 - Arbitrary File Download and Execute via Automatic Update Function

Title source: llm
STIX 2.1

Description

Insufficient Verification of input Data leading to arbitrary file download and execute was discovered in Nexacro platform. This vulnerability is caused by an automatic update function that does not verify input data except version information. Remote attackers can use this incomplete validation logic to download and execute arbitrary malicious file.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0059
EPSS Percentile 43.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-345
Status published
Products (1)
tobesoft/nexacro 17.0.0 - 17.1.3.700
Published Apr 19, 2022
Tracked Since Feb 18, 2026