CVE-2021-36356

CRITICAL EXPLOITED IN THE WILD NUCLEI

KRAMER VIAware - RCE

Title source: llm

Description

KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames (even though browseSystemFiles.php is no longer reachable via the GUI). NOTE: this issue exists because of an incomplete fix for CVE-2019-17124.

Exploits (2)

exploitdb WORKING POC
by sharkmoos · pythonremotehardware
https://www.exploit-db.com/exploits/50856
vulncheck_xdb WORKING POC
local
https://github.com/Chocapikk/CVE-2021-35064

Nuclei Templates (1)

Kramer VIAware - Remote Code Execution
CRITICALby gy741

Scores

CVSS v3 9.8
EPSS 0.9300
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2022-05-26
InTheWild.io 2022-05-26
CWE
CWE-434
Status published
Products (1)
kramerav/viaware < 2021-08
Published Aug 31, 2021
Tracked Since Feb 18, 2026