CVE-2019-13408: Advan VD-1 allows users to download arbitrary files
Published Aug 29, 2019
·Updated
A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download arbitrary files via url cgibin/ExportSettings.cgi?Download=filepath, without any authentication.
Affected Software
6 affected components
Androvideo Vd 1 Firmware<=230
Androvideo Vd 1
GeoVision Gv-vr360 Firmware<=1.10
GeoVision Gv-vr360
GeoVision Gv-vd8700 Firmware<=1.01
GeoVision Gv-vd8700
Event History
Aug 29, 2019
CVE Published
via MITRE·12:18 AM
Data Sourced
via MITRE·12:18 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-13408?
CVE-2019-13408 is a relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230.
2
How severe is CVE-2019-13408?
CVE-2019-13408 has a severity keyword of high with a CVSS severity value of 7.5.
3
How can attackers exploit CVE-2019-13408?
Attackers can exploit CVE-2019-13408 to download arbitrary files via the url cgibin/ExportSettings.cgi?Download=filepath without any authentication.