An issue in the USB Autorun function of HI-SCAN 6040i Hitrax HX-03-19-I allows attackers to execute arbitrary code via uploading a crafted script from a USB device.
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.