The WebApp v04.68 in the supervisor on SAET Impianti Speciali TEBE Small 05.01 build 1137 devices allows remote attackers to execute or include local .php files, as demonstrated by menu=php://filter/convert.base64-encode/resource=index.php to read index.php.
| Software | From | Fixed in |
|---|---|---|
| saet / tebe_small_firmware | 05.01-1137 | 05.01-1137.x |
| saet / webapp | 04.68 | 04.68.x |