Aviatrix Controller 6.x before 6.5-1804.1922 contains a vulnerability that allows unrestricted upload of a file with a dangerous type, which allows an unauthenticated user to execute arbitrary code via directory traversal.
View the template here CVE-2021-40870.yaml
References:
https://github.com/ARPSyndicate/cvemon