{"api_version":"1","generated_at":"2026-07-23T10:00:35+00:00","cve":"CVE-2018-15137","urls":{"html":"https://cve.report/CVE-2018-15137","api":"https://cve.report/api/cve/CVE-2018-15137.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-15137","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-15137"},"summary":{"title":"CVE-2018-15137","description":"CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes remote code execution as well. Because of the WebDAV feature, it is possible to upload arbitrary files by utilizing the PUT method.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-08-08 00:29:00","updated_at":"2018-10-23 17:16:00"},"problem_types":["CWE-434"],"metrics":[],"references":[{"url":"https://www.exploit-db.com/exploits/45021/","name":"45021","refsource":"EXPLOIT-DB","tags":["Third Party Advisory","VDB Entry"],"title":"Cela Link CLR-M20 2.7.1.6 - Arbitrary File Upload - Hardware webapps Exploit","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://github.com/safakaslan/CelaLinkCLRM20/issues/1","name":"https://github.com/safakaslan/CelaLinkCLRM20/issues/1","refsource":"MISC","tags":["Third Party Advisory"],"title":"Arbitrary File Upload Cela Link CLR-M20 · Issue #1 · safakaslan/CelaLinkCLRM20 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-15137","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-15137","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"15137","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"cela_link","cpe5":"clr-m20","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"15137","vulnerable":"0","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"cela_link","cpe5":"clr-m20","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"15137","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cela_link","cpe5":"clr-m20_firmware","cpe6":"2.7.1.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"15137","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cela_link","cpe5":"clr-m20_firmware","cpe6":"2.7.1.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2018-15137","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes remote code execution as well. Because of the WebDAV feature, it is possible to upload arbitrary files by utilizing the PUT method."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://github.com/safakaslan/CelaLinkCLRM20/issues/1","refsource":"MISC","url":"https://github.com/safakaslan/CelaLinkCLRM20/issues/1"},{"name":"45021","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/45021/"}]}},"nvd":{"publishedDate":"2018-08-08 00:29:00","lastModifiedDate":"2018-10-23 17:16:00","problem_types":["CWE-434"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":10},"severity":"HIGH","exploitabilityScore":10,"impactScore":10,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:cela_link:clr-m20_firmware:2.7.1.6:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:cela_link:clr-m20:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"15137","Ordinal":"131872","Title":"CVE-2018-15137","CVE":"CVE-2018-15137","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"15137","Ordinal":"1","NoteData":"CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes remote code execution as well. Because of the WebDAV feature, it is possible to upload arbitrary files by utilizing the PUT method.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"15137","Ordinal":"2","NoteData":"2018-08-07","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"15137","Ordinal":"3","NoteData":"2018-08-15","Type":"Other","Title":"Modified"}]}}}