VendorsGENEREXcs141_firmwareall versions
Vulnerabilities

GENEREX CS141 Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2022-47190
RCE via file upload vulnerability in Generex CS141
Published 2023-03-31 · Modified
10.0EPSS 0.016
CVE-2022-42457
Generex CS141 through 2.10 allows remote command execution by administrators via a web interface that reaches run_update in /usr/bin/gxserve-update.sh (e.g., command execution can occur via a reverse shell installed by install.sh).
Published 2022-10-06 · Modified
9.1EPSS 0.025
CVE-2022-47189
DoS via file upload vulnerability at Generex CS141
Published 2023-03-31 · Modified
9.1EPSS 0.009
CVE-2022-47186
Unrestricted Upload of File vulnerability in Generex CS141
Published 2023-09-28 · Modified
9.1EPSS 0.006
CVE-2022-47192
Admin password reset via file upload vulnerability in Generex CS141
Published 2023-03-31 · Modified
8.8EPSS 0.013
CVE-2022-47191
Privilege Escalation via file upload vulnerability at Generex CS141
Published 2023-03-31 · Modified
8.8EPSS 0.011
CVE-2022-47188
Improper Input Validation in Generex CS141
Published 2023-03-31 · Modified
7.5EPSS 0.009
CVE-2020-11420
UPS Adapter CS141 before 1.90 allows Directory Traversal. An attacker with Admin or Engineer login credentials could exploit the vulnerability by manipulating variables that reference files and by doing this achieve access to files and directories outside the web root folder. An attacker may access arbitrary files and directories stored in the file system, but integrity of the files are not jeopardized as attacker have read access rights only.
Published 2020-04-27 · Modified
6.5EPSS 0.016
CVE-2022-47187
File upload XSS vulnerability in Generex CS141
Published 2023-09-28 · Modified
6.1EPSS 0.004