Sauter: Arbitrary File Upload
Vulnerability Description
A low privileged remote attacker can upload arbitrary data masked as a png file to the affected device using the webserver API because only the file extension is verified.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-41720
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Damian Pfammatter, Daniel Hulliger from Cyber-Defence Campus armasuisse
More from Sauter
View All →Affected Vendor
Sauter
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.