CVE-2021-4471

HIGH

TG8 Firewall - Unauthenticated Credential Exposure via HTTP Directory Traversal

Title source: llm
STIX 2.1

Description

TG8 Firewall exposes a directory such as /data/ over HTTP without authentication. This directory stores credential files for previously logged-in users. A remote unauthenticated attacker can enumerate and download files within the directory to obtain valid account usernames and passwords, leading to loss of confidentiality and further unauthorized access.

Scores

CVSS v4 8.7
EPSS 0.0058
EPSS Percentile 42.9%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-538
Status published
Products (1)
TG8/TG8 Firewall
Published Nov 14, 2025
Tracked Since Feb 18, 2026