First published: Thu Jan 07 2021(Updated: )
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (for authentication bypass) to the web server, as demonstrated by the /loginLess/../../etc/passwd URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mercusys Mercury X18g Firmware | =1.0.5 | |
MERCUSYS Mercury X18G |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23241 is a vulnerability in MERCUSYS Mercury X18G 1.0.5 devices that allows Directory Traversal, which can be exploited for authentication bypass.
CVE-2021-23241 has a severity rating of 5.3, which is considered medium.
CVE-2021-23241 affects MERCUSYS Mercury X18G firmware version 1.0.5 by allowing Directory Traversal via ../ in conjunction with a loginLess or login.htm URI, enabling an attacker to bypass authentication.
No, MERCUSYS Mercury X18G devices are not vulnerable to CVE-2021-23241.
To fix CVE-2021-23241 vulnerability, it is recommended to update the MERCUSYS Mercury X18G firmware to a version that is not affected by the vulnerability.