Showing 1 vulnerability on this page for GoIP-1

Signals CISA KEV Ransomware Nuclei
DBL Technology (DBLTek) vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

DBLTek GoIP-1 vGHSFVT-1.1-67-5 Unauthenticated LFI

DBLTek GoIP-1 firmware versions up to and including GHSFVT-1.1-67-5 contain a local file inclusion vulnerability. The device's web server exposes handlers (`frame.html` and `frame.A100.html`) that accept a path parameter (`content` or `sidebar`) which is not properly validated or canonicalized. An attacker can supply directory-traversal sequences to cause the server to read and return arbitrary filesystem files that the webserver user can access. Other GoIP models and firmware versions are likel

CWE-22CWE-98Nov 12, 2025
CVSS8.7v4.0EPSS0.496%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX