CVE-2018-14918
loytec lgate-902_firmware Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2018-14918 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
LOYTEC LGATE-902 6.3.2 devices allow Directory Traversal.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 26, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
lgate-902_firmwareBrowse loytec / lgate-902_firmware | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHLOYTEC LGATE-902 6.3.2 - Local File InclusionCVSS 7.5
LOYTEC LGATE-902 6.3.2 is susceptible to local file inclusion which could allow an attacker to manipulate path references and access files and directories (including critical system files) that are stored outside the root folder of the web application running on the device. This can be used to read and configuration files containing, e.g., usernames and passwords.
Impact
Successful exploitation of this vulnerability could allow an attacker to read sensitive files on the device, potentially leading to unauthorized access or information disclosure.
Remediation
Apply the latest firmware update provided by LOYTEC to fix the LFI vulnerability.
Source: ProjectDiscovery