Hiby Music Hiby OS R3 Pro 1.5 and 1.6 is vulnerable to Directory Traversal. The HTTP Server does not have enough input data sanitization when shown data from SD Card, an attacker can navigate through the device's File System over HTTP.
References
Link | Resource |
---|---|
https://github.com/feric/Findings/tree/main/Hiby/Web%20Server/Path%20Traversal | Exploit Third Party Advisory |
https://github.com/vext01/hiby-issues/issues/9#issuecomment-907891626 | Exploit Third Party Advisory |
https://github.com/feric/Findings/tree/main/Hiby/Web%20Server/Path%20Traversal | Exploit Third Party Advisory |
https://github.com/vext01/hiby-issues/issues/9#issuecomment-907891626 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 06:30
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/feric/Findings/tree/main/Hiby/Web%20Server/Path%20Traversal - Exploit, Third Party Advisory | |
References | () https://github.com/vext01/hiby-issues/issues/9#issuecomment-907891626 - Exploit, Third Party Advisory |
Information
Published : 2022-03-28 16:15
Updated : 2024-11-21 06:30
NVD link : CVE-2021-44124
Mitre link : CVE-2021-44124
CVE.ORG link : CVE-2021-44124
JSON object : View
Products Affected
hiby
- r3_pro
- r3_pro_firmware
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')