CVE-2021-40870
Aviatrix Controller Unrestricted Upload of File
- Published
- Sep 13, 2021
- Updated
- Oct 21, 2025
- Assigning CNA
- mitre
- Evidence observed
- Jan 18, 2022
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.8%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.
Sources
4- CVE-2021-40870Exploit
Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file which allows an unauthenticated user to execute arbitrary code via directory traversal
Unrestricted upload of file with dangerous type in Aviatrix allows an authenticated user to execute arbitrary code
- CVE-2021-40870Exploit
Aviatrix allows an authenticated user to execute arbitrary code
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.