PT-2025-50080 · Unknown · Snmp Web Pro
Published
2025-12-09
·
Updated
2025-12-22
·
CVE-2025-65287
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SNMP Web Pro version 1.1
Description
An unauthenticated directory traversal issue exists in the
cgi-bin/upload.cgi component. The component concatenates user-supplied parameters directly onto a base path (/var/www/files/userScript/) using memcpy and strcat without proper validation or sanitization. This allows attackers to use "../" sequences to access files outside the intended directory. Additionally, the download functionality echoes unsanitized parameters into the Content-Disposition header, potentially leading to header injection.Recommendations
Apply updates to address the issue in SNMP Web Pro version 1.1.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snmp Web Pro