CVE-2019-15119: Ehang-Io Nps
Medium severity, CVSS 5.5. EPSS: 1% chance of exploitation in the next 30 days.
lib/install/install.go in cnlh nps through 0.23.2 uses 0777 permissions for /usr/local/bin/nps and/or /usr/bin/nps, leading to a file overwrite by a local user.
Affected products
- Ehang-Io Nps: up to and including 0.23.2
Published 2019-08-16. Last modified 2026-06-17.