CVE-2026-102143
Received Received - Intake

Unauthenticated File Write in Appliance Firmware

Vulnerability report for CVE-2026-102143, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description

An unauthenticated attacker could cause a file with attacker-controlled content to be written to the appliance filesystem through an administrative upload handler that did not properly authenticate the request. This did not by itself result in code execution, which would require a separate vulnerability to place the file in an executable location.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an unauthenticated attacker to write a file with malicious content to the system's filesystem through an administrative upload handler that fails to verify user permissions. While it does not directly execute code, it could enable further attacks if combined with another vulnerability to place the file in a location where it can run.

Impact Analysis

An attacker could exploit this to store harmful files on your system, potentially leading to data theft, system compromise, or unauthorized access. It may also serve as a stepping stone for more severe attacks if additional vulnerabilities exist.

Compliance Impact

This vulnerability could lead to unauthorized file writes on the appliance filesystem, potentially violating data integrity and confidentiality requirements under standards like GDPR and HIPAA. Uncontrolled file uploads may expose sensitive data or enable further attacks, impacting compliance with data protection regulations.

Mitigation Strategies

Apply vendor patches or updates to fix the authentication bypass in the administrative upload handler. Review and restrict access to administrative upload functions. Monitor filesystem changes for unexpected files. Ensure uploaded files are stored in non-executable locations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102143. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart