CVE-2023-27105

CRITICAL

Shanling M5S/M2X <4.3/3.3 - Path Traversal

Title source: llm
STIX 2.1

Description

A vulnerability in the Wi-Fi file transfer module of Shanling M5S Portable Music Player with Shanling MTouch OS v4.3 and Shanling M2X Portable Music Player with Shanling MTouch OS v3.3 allows attackers to arbitrarily read, delete, or modify any critical system files via directory traversal.

References (2)

Core 2
Core References
Exploit, Third Party Advisory
https://hexavector.github.io/4bf46f12/

Scores

CVSS v3 9.8
EPSS 0.0134
EPSS Percentile 67.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-22
Status published
Products (2)
shanling/eddict_player 2.1.3
shanling/mtouch_os 3.3
Published Apr 25, 2023
Tracked Since Feb 18, 2026