mod_webd.TFTPUploadIperf of the file /api/inner/tftpuploadiperf of the component Web FastCGI Service. The manipulation of the argument ip/port leads to command injection.This vulnerability is referenced as CVE-2026-12223. The attack needs to be initiated within the local network. Furthermore, an exploit is available.
Upgrading the affected component is recommended.
The vendor explains: "It has been fixed (...) for our technical support branch. However, please note that this specific support branch firmware is not publicly released yet."
SOCIAL SHARE CARD GENERATOR