VendorsNascentremkon_device_manager4.0.0.0
Vulnerabilities

Nascent Remkon Device Manager 4.0.0.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2021-38613
The assets/index.php Image Upload feature of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to upload any code to the target system and achieve remote code execution.
Published 2021-08-24 · Modified
10.0EPSS 0.045
CVE-2021-38611
A command-injection vulnerability in the Image Upload function of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to execute arbitrary commands, as root, via shell metacharacters in the filename parameter to assets/index.php.
Published 2021-08-24 · Modified
10.0EPSS 0.019
CVE-2021-38612
In NASCENT RemKon Device Manager 4.0.0.0, a Directory Traversal vulnerability in a log-reading function in maintenance/readLog.php allows an attacker to read any file via a specialized URL.
Published 2021-08-24 · Modified
7.5EPSS 0.017