CVE-2021-36356
CRITICAL EXPLOITED IN THE WILD NUCLEIKRAMER VIAware - RCE
Title source: llmDescription
KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames (even though browseSystemFiles.php is no longer reachable via the GUI). NOTE: this issue exists because of an incomplete fix for CVE-2019-17124.
Exploits (2)
Nuclei Templates (1)
Kramer VIAware - Remote Code Execution
CRITICALby gy741
Scores
CVSS v3
9.8
EPSS
0.9300
EPSS Percentile
99.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2022-05-26
InTheWild.io
2022-05-26
CWE
CWE-434
Status
published
Products (1)
kramerav/viaware
< 2021-08
Published
Aug 31, 2021
Tracked Since
Feb 18, 2026