← Back to all advisories
High

ZOLL DefibDashboard Unrestricted Upload

Advisory ID
L9-42-480
Category
Unrestricted Upload of File with Dangerous Type
Vendor
ZOLL
Product
Defibrillator Dashboard
Affected Version
1.2
First Published
August 10, 2021
Last Updated
October 27, 2025
Impact
High

Risk Summary

ZOLL's DefibDashboard is fleet management software for the R-Series of defibrillators. The Wi-Fi-enabled defibrillators upload regular maintenance and diagnostic information to this dashboard for readiness monitoring by biomedical engineering teams. In affected versions, a low-privileged user can upload dangerous files to the Device Check File (DCF) facility, resulting in the ability to execute arbitrary commands on the underlying operating system.

Technical Details

For details on this and other responsibly disclosed DefibDashboard vulnerabilities, see the CISA advisory: ICSMA-21-161-01.

File upload

Files submitted to the DCF facility (at /DefibDashboard/Upload.aspx) are saved to the 'Upload' directory directly beneath the web root (at /DefibDashboard/Upload/).

Because the application places unchecked user-controlled files in an executable environment under the web root, a threat actor can upload a file containing ASP.NET code and the server will process the directives, resulting in remote code execution.

The DefibDashboard application ships in a precompiled state (updatable=false), so simply uploading a new ASPX file does not result in code execution. Execution is achieved in the context of IIS by uploading a web.config file embedded with ASP code, a technique discussed here.

Questions

Common questions about the ZOLL DefibDashboard unrestricted upload.

What is the ZOLL DefibDashboard unrestricted upload vulnerability?

In DefibDashboard version 1.2, a low privileged user can upload dangerous files to the Device Check File facility, which leads to arbitrary command execution on the underlying operating system. Advisory L9-42-480 lists the category as unrestricted upload of file with dangerous type and the impact as High.

What is ZOLL DefibDashboard used for?

DefibDashboard is fleet management software for the ZOLL R-Series of defibrillators. The Wi-Fi enabled defibrillators upload regular maintenance and diagnostic information to the dashboard, which biomedical engineering teams use for readiness monitoring. Advisory L9-42-480 covers version 1.2 of that software.

What access does an attacker need to exploit DefibDashboard?

Exploiting the DefibDashboard upload needs only a low privileged user account. Files submitted to the Device Check File facility are saved to an Upload directory sitting directly beneath the web root, which places unchecked user controlled files in an executable environment on the server.

Why does a precompiled ASP.NET application still allow code execution?

The DefibDashboard application ships precompiled, with updatable set to false, so simply uploading a new ASPX file does not run it. The advisory states execution is achieved in the context of IIS instead by uploading a web.config file with ASP code embedded in it.

Is there a CISA advisory for the ZOLL DefibDashboard vulnerabilities?

Yes. The advisory points to CISA advisory ICSMA-21-161-01 for details on this and other responsibly disclosed DefibDashboard vulnerabilities. The ELTON advisory, L9-42-480, was first published on August 10, 2021 and last updated on October 27, 2025. The affected product is listed as Defibrillator Dashboard version 1.2.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 MigrationProduct Tour
Solutions
Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Subscription TestingAI-NativeFDA-Compliant RatingsVerified ExploitabilityELTON vs. Legacy TestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersContact Meet ELTON