Record summary

CVE-2024-0939 has a selected CVSS score of 6.3 (medium); EIP currently links 1 Nuclei template.

Description

A vulnerability has been found in Byzoro Smart S210 Management Platform up to 20240117 and classified as critical. This vulnerability affects unknown code of the file /Tool/uploadfile.php. The manipulation of the argument file_upload leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252184. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 8, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List20240117affected

Nuclei templates

1
ProjectDiscoveryCRITICALSmart S210 Management Platform - Arbitary File UploadCVSS 9.8

A vulnerability has been found in Byzoro Smart S210 Management Platform up to 20240117 and classified as critical. This vulnerability affects unknown code of the file /Tool/uploadfile.php. The manipulation of the argument file_upload leads to unrestricted upload.

Impact

Unauthenticated attackers can upload arbitrary PHP files through the uploadfile.php component and execute malicious code on the server, potentially compromising the entire Smart S210 management platform and connected IoT devices.

Remediation

Update Byzoro Smart S210 firmware to a version newer than 20240117 that validates file types, restricts executable uploads, and implements proper access controls on the upload functionality.

WeaknessesCWE-434
AuthorsDhiyaneshDk
Template tagscvecve2024smartfile-uploadintrusivercevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:byzoro:smart_s210_firmware:*:*:*:*:*:*:*:*
FOFA: body="Smart管理平台"

Source: ProjectDiscovery

References

5
Submit #269268 | Beijing Baizhuo Network Technology Co., Ltd. Smart S210 multi-service security gateway intelligent management platform Smart S210 arbitrary file upload vulnerabilityThird-party advisory
https://vuldb.com/?submit.269268