CVE-2019-15119: Ehang-Io Nps

Medium severity, CVSS 5.5. EPSS: 1% chance of exploitation in the next 30 days.

lib/install/install.go in cnlh nps through 0.23.2 uses 0777 permissions for /usr/local/bin/nps and/or /usr/bin/nps, leading to a file overwrite by a local user.

Affected products

  • Ehang-Io Nps: up to and including 0.23.2

Published 2019-08-16. Last modified 2026-06-17.