CVE-2019-17187

/var/WEB-GUI/cgi-bin/downloadfile.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication Directory Traversal for reading arbitrary files.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:fiberhome:hg2201t_firmware:1.00.m5007_js_201804:*:*:*:*:*:*:*
cpe:2.3:h:fiberhome:hg2201t:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:31

Type Values Removed Values Added
References () https://gist.github.com/ztz472947849/d62e7b6f4831b55c338ef22432eca06d - Exploit, Third Party Advisory () https://gist.github.com/ztz472947849/d62e7b6f4831b55c338ef22432eca06d - Exploit, Third Party Advisory

Information

Published : 2019-10-08 15:15

Updated : 2024-11-21 04:31


NVD link : CVE-2019-17187

Mitre link : CVE-2019-17187

CVE.ORG link : CVE-2019-17187


JSON object : View

Products Affected

fiberhome

  • hg2201t
  • hg2201t_firmware
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')