First published: Thu Jan 07 2021(Updated: )
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ to the UPnP server, as demonstrated by the /../../conf/template/uhttpd.json URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mercusys Mercury X18g Firmware | =1.0.5 | |
MERCUSYS Mercury X18G |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23242 is a vulnerability in MERCUSYS Mercury X18G 1.0.5 devices that allows Directory Traversal via ../ to the UPnP server.
CVE-2021-23242 affects MERCUSYS Mercury X18G 1.0.5 devices by allowing Directory Traversal via ../ to the UPnP server, as demonstrated by the /../../conf/template/uhttpd.json URI.
The severity of CVE-2021-23242 is medium with a CVSS score of 5.3.
To fix CVE-2021-23242, it is recommended to apply the latest firmware update provided by MERCUSYS.
You can find more information about CVE-2021-23242 on the reference links provided: [GitHub](https://github.com/BATTZION/MY_REQUEST/blob/master/Mercury%20Router%20Upnp%20Server%20Directory%20Traversal.md), [MERCUSYS Official Website](https://www.mercurycom.com.cn/product-521-1.html), [MERCUSYS Support](https://www.mercusys.com/en/).