CVE-2021-23241: Path Traversal
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (for authentication bypass) to the web server, as demonstrated by the /loginLess/../../etc/passwd URI.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-23241?
CVE-2021-23241 is a vulnerability in MERCUSYS Mercury X18G 1.0.5 devices that allows Directory Traversal, which can be exploited for authentication bypass.
How severe is CVE-2021-23241?
CVE-2021-23241 has a severity rating of 5.3, which is considered medium.
How does CVE-2021-23241 affect MERCUSYS Mercury X18G firmware version 1.0.5?
CVE-2021-23241 affects MERCUSYS Mercury X18G firmware version 1.0.5 by allowing Directory Traversal via ../ in conjunction with a loginLess or login.htm URI, enabling an attacker to bypass authentication.
Is MERCUSYS Mercury X18G device vulnerable to CVE-2021-23241?
No, MERCUSYS Mercury X18G devices are not vulnerable to CVE-2021-23241.
How can I fix CVE-2021-23241 vulnerability?
To fix CVE-2021-23241 vulnerability, it is recommended to update the MERCUSYS Mercury X18G firmware to a version that is not affected by the vulnerability.