---
id: CVE-2026-30284
title: >-
  An arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder v10.0
  allows attackers to overwrite critical internal files via the file import
  process, leading to arbitrary code execution or information exposure.
summary: >-
  An arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder v10.0
  allows attackers to overwrite critical internal files via the file import
  process, leading to arbitrary code execution or information exposure.
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'
cwe:
  - CWE-73
vendor: uxgroupllc
product: voice_recorder
affected:
  - voice_recorder = 10.0
published: '2026-03-31'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-30284'
references:
  - url: 'https://appcraze.co/'
    label: cve@mitre.org
  - url: 'https://github.com/Secsys-FDU/AF_CVEs/issues/25'
    label: cve@mitre.org
  - url: 'https://secsys.fudan.edu.cn/'
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00207
epssPercentile: 0.09605
ingestedAt: '2026-07-24T20:38:02.286Z'
---

## Overview

An arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder v10.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

## Affected

- `voice_recorder = 10.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
