CVE-2020-19360

HIGH NUCLEI

Fhem - Path Traversal

Title source: rule

Description

Local file inclusion in FHEM 6.0 allows in fhem/FileLog_logWrapper file parameter can allow an attacker to include a file, which can lead to sensitive information disclosure.

Exploits (2)

nomisec WORKING POC
by zzzz966 · poc
https://github.com/zzzz966/CVE-2020-19360
nomisec WORKING POC
by a1665454764 · poc
https://github.com/a1665454764/CVE-2020-19360

Nuclei Templates (1)

FHEM 6.0 - Local File Inclusion
HIGHby 0x_Akoko

Scores

CVSS v3 7.5
EPSS 0.8710
EPSS Percentile 99.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (1)
fhem/fhem 6.0
Published Jan 20, 2021
Tracked Since Feb 18, 2026