CVE-2023-46295
CRITICALTeledyne FLIR M300 2.00-19 - Unauthenticated Remote Code Execution via PHP Page
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-46295. PoCs published by Manouchehri.
AI-analyzed exploit summary The repository describes an unauthenticated remote code execution vulnerability in Teledyne FLIR M300's web server, exploitable via a crafted POST request to a vulnerable PHP page, leading to root privilege escalation via sudo. The vulnerability was fixed in firmware version 2.00-38.
Description
An issue was discovered in Teledyne FLIR M300 2.00-19. Unauthenticated remote code execution can occur in the web server. An attacker can exploit this by sending a POST request to the vulnerable PHP page. An attacker can elevate to root permissions with Sudo.
Exploits (1)
The repository describes an unauthenticated remote code execution vulnerability in Teledyne FLIR M300's web server, exploitable via a crafted POST request to a vulnerable PHP page, leading to root privilege escalation via sudo. The vulnerability was fixed in firmware version 2.00-38.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H