Vulnerability record · CVE-2021-36356 · published 31 August 2021
CVE-2021-36356: KRAMER VIAware unauthenticated file upload leads to remote code execution
Kramerav · Viaware
KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames, even though browseSystemFiles.php is no longer reachable through the GUI. The issue is an incomplete fix for CVE-2019-17124, so the earlier hardening did not close the underlying upload path. With a CVSS 3.1 score of 9.8 and no authentication or user interaction required, this is a severe pre-auth code execution flaw.
Description
KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames (even though browseSystemFiles.php is no longer reachable via the GUI). NOTE: this issue exists because of an incomplete fix for CVE-2019-17124.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution with a 9.8 CVSS score, high EPSS, and public exploit references makes this an urgent patch target.
What it is
KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames, even though browseSystemFiles.php is no longer reachable through the GUI. The issue is an incomplete fix for CVE-2019-17124, so the earlier hardening did not close the underlying upload path. With a CVSS 3.1 score of 9.8 and no authentication or user interaction required, this is a severe pre-auth code execution flaw.
Impact
An unauthenticated remote attacker can write an executable file to a chosen path and run it, gaining code execution on the VIAware host. That typically means full control of the appliance and any data or credentials it holds.
Attack surface
Reached over the network via the ajaxPages/writeBrowseFilePathAjax.php endpoint, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.54393 (99th percentile) and references carry an Exploit tag, indicating public exploit material exists and exploitation is likely.
What to do
- Apply the vendor fix for CVE-2021-36356; confirm it fully addresses the incomplete fix for CVE-2019-17124 rather than only removing GUI reachability.
- Restrict network access to VIAware management interfaces so ajaxPages endpoints are not exposed to untrusted networks.
- Remove or disable writeBrowseFilePathAjax.php if it is not required, and audit other ajaxPages scripts for the same arbitrary-path write pattern.
- Run the VIAware service with least privilege and store web-accessible directories on a non-executable or read-only mount where feasible.
Detection
- Monitor web logs for POST requests to ajaxPages/writeBrowseFilePathAjax.php, especially from unexpected source addresses.
- Alert on new or modified executable files appearing in web-served or system paths on the VIAware host.
- Watch for unexpected child processes spawned by the web server user, which would indicate uploaded code execution.
- Correlate file-write events with subsequent process creation on the appliance to catch the upload-to-execute chain.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/166623/Kramer-VIAware-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://write-up.github.io/kramerav/ | Third Party Advisory |
| http://packetstormsecurity.com/files/166623/Kramer-VIAware-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://write-up.github.io/kramerav/ | Third Party Advisory |
Track CVE-2021-36356 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-36356), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.