vendor:
TEM Opera Plus FM Family Transmitter
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Remote Code Execution
798
CWE
Product Name: TEM Opera Plus FM Family Transmitter
Affected Version From: 35.45
Affected Version To: 35.45
Patch Exists: NO
Related CWE:
CPE: a:telecomunicazioni_elettro_milano:tem_opera_plus_fm_family_transmitter:35.45
Platforms Tested: Webserver
2023
TEM Opera Plus FM Family Transmitter 35.45 Remote Code Execution
The TEM Opera Plus FM Family Transmitter 35.45 allows unauthorized access to a vulnerable endpoint, enabling an attacker to upload a binary image to the MPFS File System without any authentication. This vulnerability can be exploited to overwrite the flash program memory containing the web server's main interfaces, leading to the execution of arbitrary code.
Mitigation:
To mitigate this vulnerability, it is recommended to restrict access to the vulnerable endpoint, implement proper authentication mechanisms, and regularly update the device firmware to address security flaws.