First published: Thu Aug 29 2019(Updated: )
A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download arbitrary files via url cgibin/ExportSettings.cgi?Download=filepath, without any authentication.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Androvideo Vd 1 | <=230 | |
Androvideo Vd 1 Firmware | ||
Geovision Gv-vr360 | <=1.10 | |
GeoVision | ||
Geovision Gv-vd8700 | <=1.01 | |
GeoVision |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13408 is a relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230.
CVE-2019-13408 has a severity keyword of high with a CVSS severity value of 7.5.
Attackers can exploit CVE-2019-13408 to download arbitrary files via the url cgibin/ExportSettings.cgi?Download=filepath without any authentication.