Description
The importFile SOAP method is vulnerable to a directory traversal attack. An unauthenticated remote attacker bypass the path restriction and upload files to arbitrary locations.
Scores
CVSS v3
9.8
EPSS
0.0014
EPSS Percentile
32.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-35
Status
published
Products (6)
Sauter/EY-modulo 5 ecos 5 ecos504/505
0.0 - Firmware v6.0
Sauter/EY-modulo 5 modu 5 modu524
0.0 - Firmware v6.0
Sauter/EY-modulo 5 modu 5 modu525
0.0 - Firmware v6.0
Sauter/modulo 6 devices modu612-LC
0.0.0 - Firmware v3.2.0
Sauter/modulo 6 devices modu660-AS
0.0.0 - Firmware v3.2.0
Sauter/modulo 6 devices modu680-AS
0.0.0 - Firmware v3.2.0
Published
Oct 22, 2025
Tracked Since
Feb 18, 2026