CVE-2019-11327
MEDIUMTopcon Positioning Net-G5 <5.2.2 - Local File Inclusion
Title source: llmDescription
An issue was discovered on Topcon Positioning Net-G5 GNSS Receiver devices with firmware 5.2.2. The web interface of the product has a local file inclusion vulnerability. An attacker with administrative privileges can craft a special URL to read arbitrary files from the device's files system.
References (1)
Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://mezdanak.de/2019/06/21/iot-full-disclosure-topcon-positioning-net-g5-receiver/
Scores
CVSS v3
4.9
EPSS
0.0137
EPSS Percentile
68.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-22
Status
published
Products (1)
topcon/net-g5_firmware
5.2.2
Published
Sep 20, 2019
Tracked Since
Feb 18, 2026