CVE-2026-30281
קריטית 9.8
תיאור (מקור, אנגלית)
An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 1% (אחוזון 000) נכון ל-26/7/2026
- CWE
- CWE-73
מוצרים מושפעים
maru: neo.maru
קישורים
- https://github.com/Secsys-FDU/AF_CVEs/issues/21 ExploitThird Party Advisory
- https://maru.xyz/ Product
- https://play.google.com/store/apps/details?id=neo.maru Product
- https://secsys.fudan.edu.cn/ Not Applicable