PT-2026-25674 · Undefined · Undefined

Sourbyte

+1

·

Published

2026-03-16

·

Updated

2026-03-16

·

CVE-2026-4233

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions ThingsGateway version 12
Description A path traversal issue exists in ThingsGateway version 12, specifically affecting an unknown part of the /api/file/download file. Manipulation of the fileName argument allows for path traversal. Remote exploitation is possible, and an exploit is publicly available. The vendor was contacted regarding this issue but did not respond.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-4233

Affected Products

Undefined