CVE-2019-25610
MEDIUMNetNumber Titan Master 7.9.1 Path Traversal via drp
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25610. PoCs published by MobileNetworkSecurity.
AI-analyzed exploit summary The exploit demonstrates a path traversal vulnerability in NetNumber Titan 7.9.1's Web GUI, allowing authenticated users to download arbitrary files (e.g., /etc/shadow) via a crafted base64-encoded path parameter in the 'drp' endpoint.
Description
NetNumber Titan Master 7.9.1 contains a path traversal vulnerability in the drp endpoint that allows authenticated users to download arbitrary files by injecting directory traversal sequences. Attackers can manipulate the path parameter with base64-encoded payloads containing ../ sequences to bypass authorization and retrieve sensitive system files like /etc/shadow.
Exploits (1)
The exploit demonstrates a path traversal vulnerability in NetNumber Titan 7.9.1's Web GUI, allowing authenticated users to download arbitrary files (e.g., /etc/shadow) via a crafted base64-encoded path parameter in the 'drp' endpoint.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N