Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 05 Aug 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Refirio
Refirio freo2 |
|
| Vendors & Products |
Refirio
Refirio freo2 |
Tue, 04 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unrestricted File Upload Enabling Arbitrary OS Command Execution in Freo2 |
Tue, 04 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 04 Aug 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative privileges for the product may upload an executable file and execute arbitrary OS commands. | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2026-08-04T13:45:29.365Z
Reserved: 2026-07-28T23:15:40.868Z
Link: CVE-2026-67243
Updated: 2026-08-04T13:44:16.534Z
Status : Received
Published: 2026-08-04T08:16:35.240
Modified: 2026-08-04T14:16:32.310
Link: CVE-2026-67243
No data.
OpenCVE Enrichment
Updated: 2026-08-05T10:21:14Z