CVE-2021-28149
hongdian h8922 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2021-28149 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.
Description
Hongdian H8922 3.0.5 devices allow Directory Traversal. The /log_download.cgi log export handler does not validate user input and allows a remote attacker with minimal privileges to download any file from the device by substituting ../ (e.g., ../../etc/passwd) This can be carried out with a web browser by changing the file name accordingly. Upon visiting log_download.cgi?type=../../etc/passwd and logging in, the web server will allow a download of the contents of the /etc/passwd file.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 7, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck | Version data not supplied | ||
Nuclei templates
1ProjectDiscoveryMEDIUMHongdian H8922 3.0.5 Devices - Local File InclusionCVSS 6.5
Hongdian H8922 3.0.5 devices are vulnerable to local file inclusion. The /log_download.cgi log export handler does not validate user input and allows a remote attacker with minimal privileges to download any file from the device by substituting ../ (e.g., ../../etc/passwd) This can be carried out with a web browser by changing the file name accordingly. Upon visiting log_download.cgi?type=../../etc/passwd and logging in, the web server will allow a download of the contents of the /etc/passwd file.
Impact
Successful exploitation of this vulnerability can result in unauthorized access to sensitive files, potentially leading to further compromise of the system.
Remediation
Apply the latest security patches or updates provided by the vendor to fix the LFI vulnerability in Hongdian H8922 3.0.5 Devices.
Source: ProjectDiscovery