Record summary

CVE-2018-14918 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

LOYTEC LGATE-902 6.3.2 devices allow Directory Traversal.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 26, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHLOYTEC LGATE-902 6.3.2 - Local File InclusionCVSS 7.5

LOYTEC LGATE-902 6.3.2 is susceptible to local file inclusion which could allow an attacker to manipulate path references and access files and directories (including critical system files) that are stored outside the root folder of the web application running on the device. This can be used to read and configuration files containing, e.g., usernames and passwords.

Impact

Successful exploitation of this vulnerability could allow an attacker to read sensitive files on the device, potentially leading to unauthorized access or information disclosure.

Remediation

Apply the latest firmware update provided by LOYTEC to fix the LFI vulnerability.

WeaknessesCWE-22
Authors0x_Akoko
Template tagscvecve2018loyteclfiseclistspacketstormlgatexssvkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:o:loytec:lgate-902_firmware:*:*:*:*:*:*:*:*
Shodan: http.html:"LGATE-902"
Shodan: http.html:"lgate-902"
FOFA: body="lgate-902"

Source: ProjectDiscovery

References

4