CVE-2026-88738

Jazzware · RT1000 Edge webUI

Jazzware RT1000 Edge webUI v. 20.0.1 allows an authenticated administrative user to upload and execute arbitrary server-side files, leading to remote code execution.

Executive summary

An unrestricted file upload vulnerability in the Jazzware RT1000 Edge webUI allows authenticated attackers to achieve remote code execution on the target system.

Vulnerability

This vulnerability resides in the upgrade package upload functionality, where an attacker with administrative privileges can upload executable files that are stored in a web-accessible directory, permitting remote code execution via direct HTTP access.

Business impact

The ability for an attacker to execute arbitrary code on the appliance poses a severe risk to organizational security, potentially leading to full system compromise and unauthorized access to internal network resources. With a CVSS score of 8.8, this vulnerability represents a high-severity threat that could result in data exfiltration, service disruption, or lateral movement within the network.

Remediation

Immediate Action: Contact Jazzware support immediately to determine if a patch or configuration update is available for version 20.0.1, and restrict administrative access to the web interface to trusted management IP addresses only.

Proactive Monitoring: Audit web server access logs for suspicious file upload requests or requests to non-standard executable files within the upload directory.

Compensating Controls: Implement a Web Application Firewall (WAF) rule to intercept and block file upload attempts that contain executable extensions or suspicious payloads directed at the upgrade interface.

Exploitation status

Public Exploit Available: No.

Analyst recommendation

Given the potential for remote code execution, this vulnerability demands prompt attention from system administrators. Organizations should prioritize restricting access to the administrative interface and coordinate with the vendor to apply necessary security updates as soon as they are released.

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.8 (3.1) from cvelistV5
  4. Analyst report written

Sources