PT-2025-46728 · Longjing Technology · Longjing Technology Bems Api

Gjoko Krstic

·

Published

2025-11-12

·

Updated

2025-11-13

·

CVE-2021-4463

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Longjing Technology BEMS API versions up to and including 1.21
Description The software contains an unauthenticated arbitrary file download issue in the 'downloads' endpoint. The fileName parameter lacks proper sanitization, enabling attackers to construct file traversal sequences and gain access to sensitive files outside the designated directory.
Recommendations Apply updates to versions prior to 1.21.

Exploit

Fix

Path traversal

Files Accessible to External Parties

Weakness Enumeration

Related Identifiers

CVE-2021-4463

Affected Products

Longjing Technology Bems Api