PT-2019-18585 · Lg · Gapm-8000+2

Published

2019-05-13

·

Updated

2021-07-21

·

CVE-2019-7404

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions LG GAMP-7100, GAPM-7200, and GAPM-8000 routers (affected versions not specified)
Description An issue allows an unauthenticated user to read a log file via an HTTP request containing its full pathname. For example, an attacker can access a log file by sending an HTTP request to a URL such as "http://192.168.0.1/var/gapm7100 ${today's date}.log" to read a filename like "gapm7100 190101.log".
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-7404

Affected Products

Gapm-7200
Gapm-8000
Lg Gamp-7100