SATO CL4/6NX Plus
cpe:2.3:o:sato-global:cl4nx_plus_firmware:*:*:*:*:*:*:*, +1 more
- < 1.15.5-r1
A vulnerability exists in SATO label printers CL4/6NX Plus and CL4/6NX-J Plus (Japan model) running firmware versions prior to 1.15.5-r1. This vulnerability allows the unrestricted upload of files with dangerous types, specifically Lua scripts, which can be executed on the system with root privileges.
Exploitation of this vulnerability allows for the execution of arbitrary Lua scripts on the affected printer with root privileges.
Users are advised to update the printer firmware to the latest version. For those unable to update due to technical reasons, a temporary workaround involves enabling the printer's firewall and disabling the WebConfig function, which can be done through the printer's settings menu.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.