MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ to the UPnP server, as demonstrated by the /../../conf/template/uhttpd.json URI.
2021-01-07T21:15:14.370
2024-11-21T05:51:26.287
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | mercusys | mercury_x18g_firmware | 1.0.5 | Yes |
Hardware | mercusys | mercury_x18g | - | No |