CVE-2015-2876: Lacie LAC9000436U Firmware

High severity, CVSS 8.8. EPSS: 2.8% chance of exploitation in the next 30 days.

Unrestricted file upload vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 allows remote attackers to execute arbitrary code by uploading a file to /media/sda2 during a Wi-Fi session.

Affected products

  • Lacie LAC9000436U Firmware: up to and including 2.3.0.014
  • Lacie LAC9000464U Firmware: up to and including 2.3.0.014
  • Seagate Goflex Sattelite: any version
  • Seagate Wireless Mobile Storage: any version
  • Seagate Wireless Plus Mobile Storage: any version

Published 2015-12-31. Last modified 2026-06-17.