PT-2019-18585 · Lg · Gapm-8000+2
Published
2019-05-13
·
Updated
2021-07-21
·
CVE-2019-7404
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
LG GAMP-7100, GAPM-7200, and GAPM-8000 routers (affected versions not specified)
Description
An issue allows an unauthenticated user to read a log file via an HTTP request containing its full pathname. For example, an attacker can access a log file by sending an HTTP request to a URL such as "http://192.168.0.1/var/gapm7100 ${today's date}.log" to read a filename like "gapm7100 190101.log".
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gapm-7200
Gapm-8000
Lg Gamp-7100