Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Karl W

Researcher fromArqiva Threat Team
#25686of 53,633
9.8Total CVSS
Vulnerabilities · 1
PT-2018-18143
9.8
2018-04-17
Appear Tv · Appear Tv Xc5100 · CVE-2018-7539
**Name of the Vulnerable Software and Affected Versions** Appear TV XC5000 and XC5100 devices with firmware 3.26.217 **Description** The issue allows an attacker to read OS files by sending a specially crafted HTTP request, such as GET /../../../../../../../../../../../../etc/passwd, to the web server (fuzzd/0.1.1) running the Maintenance Center on port TCP/8088. This can potentially lead to full compromise of the device. **Recommendations** For Appear TV XC5000 and XC5100 devices with firmware 3.26.217, consider restricting access to the Maintenance Center on port TCP/8088 as a temporary workaround until a patch is available. Avoid using the web server to access sensitive OS files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.