A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can upload a malicious file to trigger this vulnerability.
Creating and using insecure temporary files can leave application and system data vulnerable to attack.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://www.inhandnetworks.com/upload/attachment/202205/10/InHand-PSA-2022-01.pdf | vendor advisory |
https://talosintelligence.com/vulnerability_reports/TALOS-2022-1468 | exploit third party advisory technical description |