CVE-2018-7539
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
17/04/2018
Last modified:
23/05/2018
Description
On Appear TV XC5000 and XC5100 devices with firmware 3.26.217, it is possible to read OS files with a specially crafted HTTP request (such as GET /../../../../../../../../../../../../etc/passwd) to the web server (fuzzd/0.1.1) running the Maintenance Center on port TCP/8088. This can lead to full compromise of the device.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.80
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:appeartv:xc5000_firmware:3.26.217:*:*:*:*:*:*:* | ||
| cpe:2.3:h:appeartv:xc5000:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:appeartv:xc5100_firmware:3.26.217:*:*:*:*:*:*:* | ||
| cpe:2.3:h:appeartv:xc5100:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



