PT-2021-17397 · Yeastar · Yeastar Neogate Tg400

Published

2021-02-19

·

Updated

2021-03-09

·

CVE-2021-27328

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Yeastar NeoGate TG400 version 91.3.0.3
Description The issue allows an authenticated user to perform Directory Traversal, which can lead to decrypting firmware and reading sensitive information, such as passwords or decryption keys.
Recommendations For Yeastar NeoGate TG400 version 91.3.0.3, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-27328

Affected Products

Yeastar Neogate Tg400