PT-2026-5836 · Rubikon Teknoloji · Easy Transfer

Published

2026-02-03

·

Updated

2026-02-03

·

CVE-2020-37086

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Easy Transfer version 1.7 for iOS
Description A directory traversal issue allows remote attackers to access unauthorized file system paths without authentication. This is achieved by manipulating path parameters in 'GET' and 'POST' requests, enabling the listing or downloading of sensitive system files and the injection of malicious scripts into application parameters.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2020-37086

Affected Products

Easy Transfer