An issue was discovered on LG GAMP-7100, GAPM-7200, and GAPM-8000 routers. An unauthenticated user can read a log file via an HTTP request containing its full pathname, such as http://192.168.0.1/var/gapm7100_${today's_date}.log for reading a filename such as gapm7100_190101.log.
2019-05-13T14:29:02.050
2024-11-21T04:48:09.970
Modified
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | lg | gamp-7100_firmware | - | Yes |
Hardware | lg | gamp-7100 | - | No |
Operating System | lg | gapm-7200_firmware | - | Yes |
Hardware | lg | gapm-7200 | - | No |
Operating System | lg | gapm-8000_firmware | - | Yes |
Hardware | lg | gapm-8000 | - | No |