Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior...
High severity
Unreviewed
Published
Jan 31, 2023
to the GitHub Advisory Database
•
Updated Feb 14, 2023
Description
Published by the National Vulnerability Database
Jan 30, 2023
Published to the GitHub Advisory Database
Jan 31, 2023
Last updated
Feb 14, 2023
Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior use a proprietary local area network (LAN) protocol that does not verify updates to the device. An attacker could upload a malformed update file to the device and execute arbitrary code.
References