CVE-2026-30284: n/a
An arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder v10.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
AI Analysis
Technical Summary
CVE-2026-30284 describes an arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder version 10.0. The vulnerability arises from the file import functionality, which can be exploited by attackers to overwrite critical internal files. Successful exploitation may result in arbitrary code execution or information disclosure. The CVSS 3.1 vector indicates the attack requires local access with low complexity, no privileges, and user interaction, but impacts confidentiality, integrity, and availability with a scope change.
Potential Impact
If exploited, this vulnerability can lead to complete compromise of the affected system by allowing arbitrary code execution. Additionally, sensitive information may be exposed due to the ability to overwrite critical internal files. The high CVSS score reflects the significant risk to confidentiality, integrity, and availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are currently available. Until a patch is released, users should exercise caution with the file import process and restrict access to trusted users only.
CVE-2026-30284: n/a
Description
An arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder v10.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
CVSS v3.1
Score 8.6high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-30284 describes an arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder version 10.0. The vulnerability arises from the file import functionality, which can be exploited by attackers to overwrite critical internal files. Successful exploitation may result in arbitrary code execution or information disclosure. The CVSS 3.1 vector indicates the attack requires local access with low complexity, no privileges, and user interaction, but impacts confidentiality, integrity, and availability with a scope change.
Potential Impact
If exploited, this vulnerability can lead to complete compromise of the affected system by allowing arbitrary code execution. Additionally, sensitive information may be exposed due to the ability to overwrite critical internal files. The high CVSS score reflects the significant risk to confidentiality, integrity, and availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are currently available. Until a patch is released, users should exercise caution with the file import process and restrict access to trusted users only.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-03-04T00:00:00.000Z
- Cvss Version
- null
- State
- PUBLISHED
Threat ID: 69cbf4f5e6bfc5ba1d2745c4
Added to database: 03/31/2026, 16:23:17 UTC
Last enriched: 07/05/2026, 21:45:07 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 155
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.