Sceawere

Vulnerability Detail

CVE-2026-88738UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Jazzware RT1000 Unrestricted File Upload

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
20h ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An authenticated attacker can upload a server-side executable file. The uploaded file is stored in a web-accessible executable location and can be accessed directly over HTTP without authentication, resulting in remote code execution.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-09-21T22:16:59.133Z",
  "pubdate": "2026-09-21T22:16:59.133Z",
  "executiveSummary": "The Jazzware RT1000 Edge webUI (version 20.0.1) is susceptible to an unrestricted file upload vulnerability within its upgrade package upload functionality.\nThis security flaw allows an authenticated attacker to upload arbitrary server-side executable files to a directory that is directly accessible via the web server.\nBy bypassing intended file type restrictions, an attacker can achieve remote code execution (RCE) with the privileges of the web service account.\nThe vulnerability is critical as it facilitates unauthorized system control without complex exploit chains, requiring only basic authenticated access.\nThe primary risk involves full compromise of the RT1000 edge device, potentially enabling lateral movement within the network or persistent backend access.\nExploitation is straightforward, as the uploaded binaries are stored in a web-accessible path and can be triggered directly via standard HTTP requests without further authentication requirements.",
  "technicalDetails": "The vulnerability resides in the update handling mechanism of the Jazzware RT1000 Edge webUI v. 20.0.1, specifically within the logic processing firmware or software upgrade packages.\nThe root cause is an absence of server-side validation regarding the file extension, content type, and structural integrity of uploaded binaries.\nThe application fails to verify that the uploaded file conforms to a valid upgrade package signature or archive format, allowing attackers to upload malicious scripts or compiled binaries instead of legitimate update files.\nOnce an attacker uploads the malicious payload, the application improperly stores the file in an executable, web-accessible directory. Because the web server environment is configured to serve and execute files from this location, any uploaded executable can be invoked via a direct HTTP request.\nThe attack flow follows a precise sequence: First, an attacker authenticates to the webUI. Second, the attacker navigates to the update interface. Third, the attacker crafts a malicious executable payload and submits it through the file upload form. Fourth, the server accepts the file and writes it to the designated web-accessible storage path without sanitization or sandboxing.\nPost-exploitation, the attacker executes the payload by requesting the specific URL associated with the uploaded file. Upon execution, the payload runs in the context of the web application service. This grants the attacker significant control over the underlying operating system, including the ability to read sensitive configuration files, capture credentials, modify system settings, or install persistent backdoors.\nThe exploit is highly effective because it relies on native web server behaviors to trigger execution. The lack of secondary validation or execution prevention mechanisms ensures that the uploaded binary retains full capability upon invocation.\nThis vulnerability is exacerbated by the fact that once the file is uploaded, the execution phase does not require additional authentication, allowing for unauthenticated execution of remote code by any party who discovers the location of the uploaded artifact.\nFurthermore, the vulnerability exposes the system to complete loss of confidentiality, integrity, and availability, as the execution of arbitrary code facilitates unrestricted access to the Jazzware RT1000 device resources."
}
CVE-2026-88738: Jazzware RT1000 Unrestricted File Upload (HIGH Severity, CVSS: 8.8) | Sceawere