Shenzhen Debo Technology Co., Ltd. Vulnerabilities and Affected Products
Vulnerabilities associated with DBLTek GoIP-1.
Products
Clear product- DBLTek GoIP-11 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-4982HIGH | DBLTek GoIP-1 vGHSFVT-1.1-67-5 Unauthenticated LFIDBLTek GoIP-1 firmware versions up to and including GHSFVT-1.1-67-5 contain a local file inclusion vulnerability. The device's web server exposes handlers (`frame.html` and `frame.A100.html`) that accept a path parameter (`content` or `sidebar`) which is not properly validated or canonicalized. An attacker can supply directory-traversal sequences to cause the server to read and return arbitrary filesystem files that the webserver user can access. Other GoIP models and firmware versions are likel… | CVSS8.7v4.0 | EPSS0.496% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |