← Back to all advisories
High

ZOLL DefibDashboard Unrestricted Upload

Advisory ID
L9-42-480
Category
Unrestricted Upload of File with Dangerous Type
Vendor
ZOLL
Product
Defibrillator Dashboard
Affected Version
1.2
First Published
August 10, 2021
Last Updated
October 27, 2025
Impact
High

Risk Summary

ZOLL's DefibDashboard is fleet management software for the R-Series of defibrillators. The Wi-Fi-enabled defibrillators upload regular maintenance and diagnostic information to this dashboard for readiness monitoring by biomedical engineering teams. In affected versions, a low-privileged user can upload dangerous files to the Device Check File (DCF) facility, resulting in the ability to execute arbitrary commands on the underlying operating system.

Technical Details

For details on this and other responsibly disclosed DefibDashboard vulnerabilities, see the CISA advisory: ICSMA-21-161-01.

File upload

Files submitted to the DCF facility (at /DefibDashboard/Upload.aspx) are saved to the 'Upload' directory directly beneath the web root (at /DefibDashboard/Upload/).

Because the application places unchecked user-controlled files in an executable environment under the web root, a threat actor can upload a file containing ASP.NET code and the server will process the directives, resulting in remote code execution.

The DefibDashboard application ships in a precompiled state (updatable=false), so simply uploading a new ASPX file does not result in code execution. Execution is achieved in the context of IIS by uploading a web.config file embedded with ASP code, a technique discussed here.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
Platform OverviewDigital TwinAutonomous TestingExploitability VerificationVulnerability GraphRemediation OptimizationELTON TestLink™Lifecycle & MetricsCVSSv4 MigrationProduct Tour
Solutions
FDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLWPostmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory Affairs
Why ELTON
Why ELTONProof Over ProbabilityFind the 1%Not a Pentest. Not a Scanner.MDDT MethodologyCredentialsDevice ModalitiesPricingELTON vs. Consultants
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRegulatory GuidesWebinarsThe Death of PentestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersContact Book a Demo