CVE-2023-5499
HIGHShenzhen Reachfar v28 - Sensitive Information Exposure via Log Directory
Title source: llmDescription
Information exposure vulnerability in Shenzhen Reachfar v28, the exploitation of which could allow a remote attacker to retrieve all the week's logs stored in the 'log2' directory. An attacker could retrieve sensitive information such as remembered wifi networks, sent messages, SOS device locations and device configurations.
References (1)
Core 1
Core References
Scores
CVSS v3
7.5
EPSS
0.0057
EPSS Percentile
42.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-532
Status
published
Products (1)
reachfargps/reachfar_gps_firmware
28
Published
Oct 10, 2023
Tracked Since
Feb 18, 2026