Nautel VX Series transmitters VX SW v6.4.0 and below was...
Critical severity
Unreviewed
Published
Apr 18, 2025
to the GitHub Advisory Database
•
Updated Apr 22, 2025
Description
Published by the National Vulnerability Database
Apr 18, 2025
Published to the GitHub Advisory Database
Apr 18, 2025
Last updated
Apr 22, 2025
Nautel VX Series transmitters VX SW v6.4.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the firmware update process. This vulnerability allows attackers to execute arbitrary code via supplying a crafted update package to the /#/software/upgrades endpoint.
References