CVE-2025-41720
A low privileged remote attacker can upload arbitrary data masked as a png file to the affected device using the webserv
A low privileged remote attacker can upload arbitrary data masked as a png file to the affected device using the webserver API because only the file extension is verified.
MEDIUM · CVSS 4.3
EPSS 0.00025
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0