CVE-2022-4982: DBLTek GoIP-1 vGHSFVT-1.1-67-5 Unauthenticated LFI
DBLTek GoIP-1 firmware versions up to and including GHSFVT-1.1-67-5 contain a local file inclusion vulnerability. The device's web server exposes handlers (frame.html and frame.A100.html) that accept a path parameter (content or sidebar) which is not properly validated or canonicalized. An attacker can supply directory-traversal sequences to cause the server to read and return arbitrary filesystem files that the webserver user can access. Other GoIP models and firmware versions are likely affected. Exploitation evidence was observed by the Shadowserver Foundation on 2024-03-21 UTC.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-4982?
CVE-2022-4982 is classified as a medium-severity vulnerability due to its potential for local file inclusion.
How do I fix CVE-2022-4982?
To fix CVE-2022-4982, update the firmware of the DBLTek GoIP-1 to a version later than GHSFVT-1.1-67-5.
What systems are affected by CVE-2022-4982?
CVE-2022-4982 affects DBLTek GoIP-1 devices running firmware versions up to and including GHSFVT-1.1-67-5.
What type of vulnerability is CVE-2022-4982?
CVE-2022-4982 is a local file inclusion (LFI) vulnerability that arises from improper validation of input parameters.
Can exploiting CVE-2022-4982 lead to unauthorized access?
Yes, exploiting CVE-2022-4982 could allow an attacker to read arbitrary files on the affected device, leading to potential unauthorized access.