Telesquare SKT LTE Router SDT-CS3B1 WebDAV Arbitrary File Upload Vulnerability

Vulnerability

An arbitrary file upload vulnerability has been identified in the Telesquare SKT LTE Router SDT-CS3B1, specifically in version 1.2.0. This vulnerability allows unauthenticated attackers to upload malicious content by exploiting enabled WebDAV HTTP methods. The vulnerable WebDAV methods include PUT, DELETE, MKCOL, MOVE, COPY, and PROPPATCH. Attackers could use these methods to upload executable code, delete files, or manipulate server content, potentially leading to remote code execution or a denial-of-service condition.

Impact

Exploitation of this vulnerability could result in unauthorized file uploads, including executable code, which could be executed on the server. Additionally, the vulnerability could be used to delete or manipulate files on the server, causing disruption of services or creating phishing opportunities.

Reproduction

The vulnerability can be reproduced by sending a WebDAV request using the PUT method to upload a file, such as a script, to the router. After uploading, the same request can be sent using the DELETE method to remove a file, or other WebDAV methods can be used to manipulate files and directories on the server.

Added: Mar 16, 2026, 2:56 PM
Updated: Mar 16, 2026, 2:56 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.0
remediation
0.0
relevance
4.0
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.