PT-2025-46728 · Longjing Technology · Longjing Technology Bems Api
Gjoko Krstic
·
Published
2025-11-12
·
Updated
2025-11-13
·
CVE-2021-4463
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Longjing Technology BEMS API versions up to and including 1.21
Description
The software contains an unauthenticated arbitrary file download issue in the 'downloads' endpoint. The
fileName parameter lacks proper sanitization, enabling attackers to construct file traversal sequences and gain access to sensitive files outside the designated directory.Recommendations
Apply updates to versions prior to 1.21.
Exploit
Fix
Path traversal
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Longjing Technology Bems Api