THREAT OPS › Threat News › [0day-rubbish] Scan2x ScanWebClient 2.3.3.0 (other versions with the same handler are likely affected) Pre-authentication RCE (unrestricted upload to executable webroot) (9.8)
[0day-rubbish] Scan2x ScanWebClient 2.3.3.0 (other versions with the same handler are likely affected) Pre-authentication RCE (unrestricted upload to executable webroot) (9.8)
<p>Posted by disclosure via Fulldisclosure on Aug 26</p>0day Rubbish Research Team is publicly disclosing a vulnerability in Scan2x ScanWebClient 2.3.3.0 (other versions with <br /> the same handler are likely affected).<br /> <br /> Type: Pre-authentication RCE (unrestricted upload to executable webroot) (CWE-434)<br /> CVSS: 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)<br /> Impact: Unauth
Indicators of compromise
- 2.3.3.0ipv4
Original source: https://seclists.org/fulldisclosure/2026/Aug/90