PT-2021-17397 · Yeastar · Yeastar Neogate Tg400
Published
2021-02-19
·
Updated
2021-03-09
·
CVE-2021-27328
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Yeastar NeoGate TG400 version 91.3.0.3
Description
The issue allows an authenticated user to perform Directory Traversal, which can lead to decrypting firmware and reading sensitive information, such as passwords or decryption keys.
Recommendations
For Yeastar NeoGate TG400 version 91.3.0.3, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yeastar Neogate Tg400