Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious content by exploiting enabled WebDAV HTTP methods. Attackers can use PUT, DELETE, MKCOL, MOVE, COPY, and PROPPATCH methods to upload executable code, delete files, or manipulate server content for remote code execution or denial of service.
Metrics
Affected Vendors & Products
References
History
Mon, 16 Mar 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious content by exploiting enabled WebDAV HTTP methods. Attackers can use PUT, DELETE, MKCOL, MOVE, COPY, and PROPPATCH methods to upload executable code, delete files, or manipulate server content for remote code execution or denial of service. | |
| Title | Telesquare SKT LTE Router SDT-CS3B1 WebDAV Arbitrary File Upload | |
| First Time appeared |
Telesquare
Telesquare sdt-cs3b1 Telesquare sdt-cs3b1 Firmware |
|
| Weaknesses | CWE-434 | |
| CPEs | cpe:2.3:h:telesquare:sdt-cs3b1:-:*:*:*:*:*:*:* cpe:2.3:o:telesquare:sdt-cs3b1_firmware:1.1.0:*:*:*:*:*:*:* cpe:2.3:o:telesquare:sdt-cs3b1_firmware:1.2.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Telesquare
Telesquare sdt-cs3b1 Telesquare sdt-cs3b1 Firmware |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-16T01:28:27.434Z
Reserved: 2026-03-15T21:57:29.608Z
Link: CVE-2017-20224
No data.
No data.
No data.
OpenCVE Enrichment
No data.