PT-2019-13320 · Advan · Advan Vd-1

Keniver Wang

+2

·

Published

2019-08-29

·

Updated

2020-10-08

·

CVE-2019-13408

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Advan VD-1 firmware versions up to 230
Description A relative path traversal issue allows attackers to download arbitrary files without authentication via the API endpoint "/cgi-bin/ExportSettings.cgi" with the Download parameter set to filepath.
Recommendations For Advan VD-1 firmware versions up to 230, consider restricting access to the "/cgi-bin/ExportSettings.cgi" endpoint until a patch is available. As a temporary workaround, avoid using the Download parameter in the affected API endpoint.

Exploit

Fix

Relative Path Traversal

Missing Authorization

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-13408

Affected Products

Advan Vd-1