CVE-2022-4982
DBLTek GoIP-1 vGHSFVT-1.1-67-5 Unauthenticated LFI
Record summary
CVE-2022-4982 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
DBLTek GoIP-1 firmware versions up to and including GHSFVT-1.1-67-5 contain a local file inclusion vulnerability. The device's web server exposes handlers (`frame.html` and `frame.A100.html`) that accept a path parameter (`content` or `sidebar`) which is not properly validated or canonicalized. An attacker can supply directory-traversal sequences to cause the server to read and return arbitrary filesystem files that the webserver user can access. Other GoIP models and firmware versions are likely affected. Exploitation evidence was observed by the Shadowserver Foundation on 2024-03-21 UTC.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 12, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Catalogued exploits
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 13, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unknown | CVE List | Through GHSFVT-1.1-67-5 | affected |
| VulnCheck | Version data not supplied | ||