CVE-2024-34854
CRITICAL EXPLOITEDF-logic DataCube3 v1.0 - Path Traversal via File Upload in transceiver_schedule.php
Title source: llmExploitation Summary
CVE-2024-34854 has been observed exploited in the wild (reported by VulnCheck KEV).
Description
F-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.`
References (1)
Core 1
Core References
Exploit, Third Party Advisory
https://github.com/Yang-Nankai/Vulnerabilities/blob/main/DataCube3%20Shell%20Code%20Injection.md
Scores
CVSS v3
9.8
EPSS
0.0059
EPSS Percentile
69.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
VulnCheck KEV
2024-12-05
CWE
CWE-22
Status
published
Products (1)
f-logic/datacube3_firmware
1.0
Published
May 28, 2024
Tracked Since
Feb 18, 2026