ZOLL's DefibDashboard is fleet management software for the R-Series of defibrillators. The Wi-Fi-enabled defibrillators upload regular maintenance and diagnostic information to this dashboard for readiness monitoring by biomedical engineering teams. In affected versions, a low-privileged user can upload dangerous files to the Device Check File (DCF) facility, resulting in the ability to execute arbitrary commands on the underlying operating system.
For details on this and other responsibly disclosed DefibDashboard vulnerabilities, see the CISA advisory: ICSMA-21-161-01.
Files submitted to the DCF facility (at /DefibDashboard/Upload.aspx) are saved to the 'Upload' directory directly beneath the web root (at /DefibDashboard/Upload/).
Because the application places unchecked user-controlled files in an executable environment under the web root, a threat actor can upload a file containing ASP.NET code and the server will process the directives, resulting in remote code execution.
The DefibDashboard application ships in a precompiled state (updatable=false), so simply uploading a new ASPX file does not result in code execution. Execution is achieved in the context of IIS by uploading a web.config file embedded with ASP code, a technique discussed here.
In DefibDashboard version 1.2, a low privileged user can upload dangerous files to the Device Check File facility, which leads to arbitrary command execution on the underlying operating system. Advisory L9-42-480 lists the category as unrestricted upload of file with dangerous type and the impact as High.
DefibDashboard is fleet management software for the ZOLL R-Series of defibrillators. The Wi-Fi enabled defibrillators upload regular maintenance and diagnostic information to the dashboard, which biomedical engineering teams use for readiness monitoring. Advisory L9-42-480 covers version 1.2 of that software.
Exploiting the DefibDashboard upload needs only a low privileged user account. Files submitted to the Device Check File facility are saved to an Upload directory sitting directly beneath the web root, which places unchecked user controlled files in an executable environment on the server.
The DefibDashboard application ships precompiled, with updatable set to false, so simply uploading a new ASPX file does not run it. The advisory states execution is achieved in the context of IIS instead by uploading a web.config file with ASP code embedded in it.
Yes. The advisory points to CISA advisory ICSMA-21-161-01 for details on this and other responsibly disclosed DefibDashboard vulnerabilities. The ELTON advisory, L9-42-480, was first published on August 10, 2021 and last updated on October 27, 2025. The affected product is listed as Defibrillator Dashboard version 1.2.