CVE-2024-40088

MEDIUM

Vilo 5 Mesh WiFi System <= 5.16.1.33 - Path Traversal

Title source: llm
STIX 2.1

Description

A Directory Traversal vulnerability in the Boa webserver of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers to enumerate the existence and length of any file in the filesystem by placing malicious payloads in the path of any HTTP request.

Scores

CVSS v3 5.3
EPSS 0.0098
EPSS Percentile 76.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-79 CWE-116
Status published
Products (1)
viloliving/vilo_5_firmware < 5.16.1.33
Published Oct 21, 2024
Tracked Since Feb 18, 2026