CVE-2018-5997

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
25/01/2018
Last modified:
12/02/2018

Description

An issue was discovered in the HTTP Server in RAVPower Filehub 2.000.056. Due to an unrestricted upload feature and a path traversal vulnerability, it is possible to upload a file on a filesystem with root privileges: this will lead to remote code execution as root.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ravpower:filehub_firmware:2.000.056:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools