Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

eCharge Hardy Barth Salia PLCC Unrestricted File Upload Vulnerability in Web UI Component

Vulnerability

A critical vulnerability allowing unrestricted file uploads has been identified in eCharge Hardy Barth Salia PLCC version 2.2.0. This issue resides in the Web UI component, specifically within the firmware.php file. The vulnerability is triggered by manipulating the media argument, which leads to arbitrary file uploads. This flaw can be exploited remotely and has been publicly disclosed, with an available exploit. The vulnerability could potentially allow uploaded files to be executed, leading to arbitrary remote command execution.

Impact

Exploitation of this vulnerability allows for arbitrary file uploads, which could be used to execute malicious files on the server, potentially leading to arbitrary remote command execution.

Reproduction

The vulnerability can be reproduced by sending a request to the firmware.php file with a manipulated media argument that includes a file of a type that the application will process. This can be done remotely, and the uploaded file can be executed to achieve command execution on the server.

Added: Jun 9, 2025, 11:19 AM
Updated: Jun 9, 2025, 12:35 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.9
remediation
0.0
relevance
0.2
threat
8.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.