CVE-2023-45599
A CWE-646 “Reliance on File Name or Extension of Externally-Supplied File” vulnerability in the “iec61850” functionality of the web application allows a remote authenticated attacker to upload any arbitrary type of file into the device. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.5
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L
- EPSS probability
- 0.24%
- CWE
- CWE-646
- Published
- 2024-03-05
- Last modified
- 2026-03-13
Affected products
- AiLux imx6 bundle
Weakness type
Related vulnerabilities
- CVE-2026-45315 — Open WebUI: Stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions
- CVE-2026-20172 — Cisco Enterprise Chat and Email Lite Agent File Upload Vulnerability
- CVE-2025-30662 — Zoom Workplace VDI Plugin macOS Universal Installer - Symlink Following
- CVE-2025-41720 — Sauter: Arbitrary File Upload
- CVE-2025-58449 — Maho Vulnerable to Authenticated Remote Code Execution via File Upload
- CVE-2025-1889 — picklescan - Security scanning bypass via non-standard file extensions
- CVE-2024-52052 — Stream Target Remote Code Execution in Wowza Streaming Engine
- CVE-2024-38432 — Matrix – Tafnit v8 CWE-646: Reliance on File Name or Extension of Externally-Supplied File