CVE-2020-37086

MEDIUM

Easy Transfer 1.7 iOS - Path Traversal

Title source: llm
STIX 2.1

Description

Easy Transfer 1.7 iOS mobile application contains a directory traversal vulnerability that allows remote attackers to access unauthorized file system paths without authentication. Attackers can exploit the vulnerability by manipulating path parameters in GET and POST requests to list or download sensitive system files and inject malicious scripts into application parameters.

Exploits (1)

exploitdb WORKING POC
by Vulnerability-Lab · textwebappsios
https://www.exploit-db.com/exploits/48395

Scores

CVSS v3 6.2
EPSS 0.0323
EPSS Percentile 87.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
Rubikon Teknoloji/Easy Transfer 1.7
Published Feb 03, 2026
Tracked Since Feb 18, 2026