Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious content by exploiting enabled WebDAV HTTP methods. Attackers can use PUT, DELETE, MKCOL, MOVE, COPY, and PROPPATCH methods to upload executable code, delete files, or manipulate server content for remote code execution or denial of service.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 16 Mar 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious content by exploiting enabled WebDAV HTTP methods. Attackers can use PUT, DELETE, MKCOL, MOVE, COPY, and PROPPATCH methods to upload executable code, delete files, or manipulate server content for remote code execution or denial of service. | |
| Title | Telesquare SKT LTE Router SDT-CS3B1 WebDAV Arbitrary File Upload | |
| First Time appeared |
Telesquare
Telesquare sdt-cs3b1 Telesquare sdt-cs3b1 Firmware |
|
| Weaknesses | CWE-434 | |
| CPEs | cpe:2.3:h:telesquare:sdt-cs3b1:-:*:*:*:*:*:*:* cpe:2.3:o:telesquare:sdt-cs3b1_firmware:1.1.0:*:*:*:*:*:*:* cpe:2.3:o:telesquare:sdt-cs3b1_firmware:1.2.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Telesquare
Telesquare sdt-cs3b1 Telesquare sdt-cs3b1 Firmware |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-16T01:28:27.434Z
Reserved: 2026-03-15T21:57:29.608Z
Link: CVE-2017-20224
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses