Due to improper BLE security configurations on the device's GATT server, an adjacent unauthenticated attacker can read and write device control comman...
Description
Due to improper BLE security configurations on the device's GATT server, an adjacent unauthenticated attacker can read and write device control commands through the mobile app service wich could render the device unusable
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Guangzhou Red Sea Cloud Computing Co.
PRODUCT: Red Sea Cloud eHR
AFFECTED_VERSIONS: See vendor advisory
---END_METADATA---
Description Summary:
Guangzhou Red Sea Cloud eHR contains an arbitrary file upload vulnerability in the PtFjk.mob servlet, allowing unauthenticated attackers to achieve remote code execution via malicious file uploads.
Executive Summary:
An unauthenticated remote code execution flaw in Red Sea Cloud eHR allows attackers to compromise the system through malicious file uploads, with evidence of active exploitation in the wild.
Vulnerability Details
CVE-ID: CVE-2024-14037
Affected Software: Guangzhou Red Sea Cloud eHR
Affected Versions: See vendor advisory
Vulnerability: The application lacks proper MIME type and extension validation in the
PtFjk.mobservlet. Attackers can bypass security checks by spoofing the Content-Type header to upload and execute JSP webshells.Business Impact
The CVSS score of 9.8 highlights the critical nature of this flaw, which provides a direct path to total system takeover. Business consequences include the potential for unauthorized access to sensitive employee HR data, loss of system integrity, and significant operational disruption due to attacker-controlled webshells.
Remediation Plan
Immediate Action: Apply the latest security update from Guangzhou Red Sea Cloud Computing Co. immediately, as the vulnerability is currently subject to active exploitation.
Proactive Monitoring: Monitor the
/uploadfile/directory for unexpected file creations and audit web server access logs for anomalous requests to thePtFjk.mobendpoint.Compensating Controls: Implement WAF filtering to restrict file uploads to legitimate types and block requests that attempt to bypass extension validation.
Exploitation Status
Public Exploit Available: Not specified
Analyst Notes: As of Jul 2, 2026, the vulnerability is confirmed to be under active exploitation. The ability to execute arbitrary code without authentication makes this a high-priority security incident.
Analyst Recommendation
Immediate remediation is required to protect the integrity of the eHR environment. Organizations should verify that their instances are patched and perform a forensic review of system logs to ensure that no unauthorized persistence mechanisms have been established by attackers prior to patching.