All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-49201
CRITICALpublished 2026-05-29 11:16 UTC · 2 months ago · modified 2026-06-17 10:55 UTC
10.0
CVSS / 10
// description
The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, facilitating persistent backdoor injection.
// weaknesses (CWE)
- CWE-798