RAD SecFlow-2 devices with Hardware 0202, Firmware 4.1.01...
High severity
Unreviewed
Published
Mar 8, 2024
to the GitHub Advisory Database
•
Updated Aug 1, 2024
Description
Published by the National Vulnerability Database
Mar 8, 2024
Published to the GitHub Advisory Database
Mar 8, 2024
Last updated
Aug 1, 2024
RAD SecFlow-2 devices with Hardware 0202, Firmware 4.1.01.63, and U-Boot 2010.12 allow URIs beginning with /.. for Directory Traversal, as demonstrated by reading /etc/shadow.
References