CVE-2024-37038

Publication date

2024-06-12 16:51:55

Family

schneider

State

PUBLISHED

Description

CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware uploads when crafting custom web requests.