Executive brief
The Jazzware RT1000 Edge webUI contains a file upload vulnerability in its upgrade package functionality that allows remote code execution. An attacker with administrative access can upload malicious executable files that are stored in a web-accessible location and executed without authentication, leading to full compromise of the edge device.
Technical details
The RT1000 Edge webUI upgrade package upload function lacks input validation, permitting upload of arbitrary server-side executable files. Uploaded files are stored in a web-accessible directory and executed directly without signature verification or authentication checks, enabling unauthenticated remote code execution after initial admin upload.
Affected products
- Jazzware RT1000 Edge webUI 20.0.1
Timeline
- 2026-09-21: disclosed