CVE-2022-35239: Contec Sv-Cpt-MC310 Firmware
High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.
The image file management page of SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and earlier contains an insufficient verification vulnerability when uploading files. If this vulnerability is exploited, arbitrary PHP code may be executed if a remote authenticated attacker uploads a specially crafted PHP file.
Affected products
- Contec Sv-Cpt-MC310 Firmware: before 7.24 (fixed in 7.24)
- Contec Sv-Cpt-MC310F Firmware: before 7.24 (fixed in 7.24)
Published 2022-08-16. Last modified 2026-06-17.