vendor:
TEM Opera Plus FM Family Transmitter
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Remote Code Execution
434
CWE
Product Name: TEM Opera Plus FM Family Transmitter
Affected Version From: 35.45
Affected Version To: 35.45
Patch Exists: NO
Related CWE:
CPE: a:telecomunicazioni_elettro_milano:tem_opera_plus_fm_family_transmitter:35.45
Platforms Tested: Webserver
2023
TEM Opera Plus FM Family Transmitter 35.45 Remote Code Execution
The TEM Opera Plus FM Family Transmitter 35.45 allows unauthorized access to an endpoint enabling the upload of binary images to the MPFS File System without authentication. By leveraging this flaw, an attacker can overwrite the flash program memory hosting the web server's main interfaces and run arbitrary code.
Mitigation:
To mitigate this vulnerability, it is recommended to restrict network access to the affected device, apply the principle of least privilege, and ensure that strong authentication mechanisms are in place to prevent unauthorized access.