The WebApp v04.68 in the supervisor on SAET Impianti Speciali TEBE Small 05.01 build 1137 devices allows remote attackers to execute or include local .php files, as demonstrated by menuphp://filter/convert.base64-encode/resourceindex.php to read index.php.
Publication date: Sat, 01 Jun 2019 03:29:00 +0000