CVE-2021-4471
Severity CVSS v4.0:
HIGH
Type:
CWE-538
Insertion of Sensitive Information into Externally-Accessible File or Directory
Publication date:
14/11/2025
Last modified:
14/11/2025
Description
TG8 Firewall exposes a directory such as /data/ over HTTP without authentication. This directory stores credential files for previously logged-in users. A remote unauthenticated attacker can enumerate and download files within the directory to obtain valid account usernames and passwords, leading to loss of confidentiality and further unauthorized access.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH



