← Vulnerability feed

Vulnerability record · CVE-2021-36356 · published 31 August 2021

CVE-2021-36356: KRAMER VIAware unauthenticated file upload leads to remote code execution

Kramerav · Viaware

KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames, even though browseSystemFiles.php is no longer reachable through the GUI. The issue is an incomplete fix for CVE-2019-17124, so the earlier hardening did not close the underlying upload path. With a CVSS 3.1 score of 9.8 and no authentication or user interaction required, this is a severe pre-auth code execution flaw.

9.8 CVSS 3.1 Critical EPSS 54% · top 1.0% CWE-434 · Unrestricted file upload
9.8CVSS 3.1 base score, v2 10.0
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames (even though browseSystemFiles.php is no longer reachable via the GUI). NOTE: this issue exists because of an incomplete fix for CVE-2019-17124.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable remote code execution with a 9.8 CVSS score, high EPSS, and public exploit references makes this an urgent patch target.

What it is

KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames, even though browseSystemFiles.php is no longer reachable through the GUI. The issue is an incomplete fix for CVE-2019-17124, so the earlier hardening did not close the underlying upload path. With a CVSS 3.1 score of 9.8 and no authentication or user interaction required, this is a severe pre-auth code execution flaw.

Impact

An unauthenticated remote attacker can write an executable file to a chosen path and run it, gaining code execution on the VIAware host. That typically means full control of the appliance and any data or credentials it holds.

Attack surface

Reached over the network via the ajaxPages/writeBrowseFilePathAjax.php endpoint, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is 0.54393 (99th percentile) and references carry an Exploit tag, indicating public exploit material exists and exploitation is likely.

What to do

  • Apply the vendor fix for CVE-2021-36356; confirm it fully addresses the incomplete fix for CVE-2019-17124 rather than only removing GUI reachability.
  • Restrict network access to VIAware management interfaces so ajaxPages endpoints are not exposed to untrusted networks.
  • Remove or disable writeBrowseFilePathAjax.php if it is not required, and audit other ajaxPages scripts for the same arbitrary-path write pattern.
  • Run the VIAware service with least privilege and store web-accessible directories on a non-executable or read-only mount where feasible.

Detection

  • Monitor web logs for POST requests to ajaxPages/writeBrowseFilePathAjax.php, especially from unexpected source addresses.
  • Alert on new or modified executable files appearing in web-served or system paths on the VIAware host.
  • Watch for unexpected child processes spawned by the web server user, which would indicate uploaded code execution.
  • Correlate file-write events with subsequent process creation on the appliance to catch the upload-to-execute chain.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-36356 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-35064KramerAV VIAWare sudo misconfiguration privilege escalationKramerAV VIAWare ships with a sudoers configuration that lets users run dangerous commands such as unzip, systemctl and dpkg. Because those commands …EPSS 71%analysed9.8CVE-2019-17124Kramerav viaware incorrect default permissions vulnerabilityKramer VIAware 2.5.0719.1034 has Incorrect Access Control.EPSS 23%10.0CVE-2026-56291Balbooa Forms Joomla extension unauthenticated arbitrary file upload RCEThe Balbooa Forms extension for Joomla before version 2.4.1 accepts file uploads without authentication and does not restrict file type, allowing exe…KEVEPSS 15%analysed10.0CVE-2026-48939iCagenda Joomla extension unrestricted file upload leads to PHP RCEThe iCagenda extension for Joomla fails to restrict file types in its file attachment feature, allowing arbitrary file uploads that result in PHP cod…KEVEPSS 20%analysed10.0CVE-2026-56290Joomla Page Builder CK unauthenticated file upload leads to RCEThe Joomla Page Builder CK extension before 3.6.0 allows unauthenticated arbitrary file uploads, letting an attacker place executable files on the se…KEVEPSS 31%analysed10.0CVE-2026-48908SP Page Builder for Joomla unauthenticated arbitrary file upload RCESP Page Builder for Joomla permits unauthenticated users to upload arbitrary files, which can lead to upload and execution of PHP code. The flaw is a…KEVEPSS 89%analysed9.8CVE-2024-7399Samsung MagicINFO 9 Server path traversal allows arbitrary file writeSamsung MagicINFO 9 Server before version 21.1050 contains a path traversal flaw (CWE-22) that also enables unrestricted file upload (CWE-434), letti…KEVEPSS 92%analysed7.2CVE-2025-2749Kentico Xperience path traversal and file upload lead to RCEKentico Xperience through 13.0.178 allows an authenticated Staging Sync Server user to upload arbitrary data to relative paths, enabling path travers…KEVEPSS 4.1%analysed

Source: NIST National Vulnerability Database (record CVE-2021-36356), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.