CVE-2021-4463

HIGH NUCLEI

Longjing Technology BEMS API <=1.21 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-4463. PoCs published by LiquidWorm. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit demonstrates an unauthenticated arbitrary file download vulnerability in Longjing Technology BEMS API 1.21 via directory traversal attacks. The PoC uses curl commands to retrieve sensitive files like /etc/passwd and /etc/shadow.

Description

Longjing Technology BEMS API versions up to and including 1.21 contains an unauthenticated arbitrary file download vulnerability in the 'downloads' endpoint. The 'fileName' parameter is not properly sanitized, allowing attackers to craft traversal sequences and access sensitive files outside the intended directory.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textwebappshardware
https://www.exploit-db.com/exploits/50163

This exploit demonstrates an unauthenticated arbitrary file download vulnerability in Longjing Technology BEMS API 1.21 via directory traversal attacks. The PoC uses curl commands to retrieve sensitive files like /etc/passwd and /etc/shadow.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Longjing Technology BEMS API 1.21
No auth needed
Prerequisites: Network access to the vulnerable API endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Longjing Technology BEMS API 1.21 - Unauthenticated Arbitrary File Download
HIGHby gy741

References (7)

Core 7
Core References
Third Party Advisory technical-description exploit
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5657.php
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/50163
Exploit, Third Party Advisory exploit
https://packetstormsecurity.com/files/163702
Third Party Advisory, VDB Entry vdb-entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/206477

Scores

CVSS v4 8.7
EPSS 0.0114
EPSS Percentile 62.3%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22 CWE-552
Status published
Products (1)
Shenzhen Longjing Technology Co. Ltd./BEMS API < 1.21
Published Nov 12, 2025
Tracked Since Feb 18, 2026