Description
An arbitrary file read vulnerability in Adguard Home before v0.107.52 allows authenticated attackers to access arbitrary files as root on the underlying Operating System via placing a crafted file into a readable directory.
References (4)
Core 4
Core References
Various Sources
https://happy-little-accidents.pages.dev/posts/CVE-2024-36814/
Various Sources
https://github.com/AdguardTeam/AdGuardHome/
Various Sources
https://github.com/AdguardTeam/AdGuardHome/blob/7c002e1a99b9b4e4a40e8c66851eda33e666d52d/internal/filtering/http.go#L23C1-L51C2
Various Sources
https://github.com/itz-d0dgy/
Scores
CVSS v3
4.9
EPSS
0.0039
EPSS Percentile
59.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (1)
AdguardTeam/AdGuardHome
0 - 0.107.53Go
Published
Oct 08, 2024
Tracked Since
Feb 18, 2026