CVE-2022-47188

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
31/03/2023
Last modified:
06/04/2023

Description

There is an arbitrary file reading vulnerability in Generex UPS CS141 below 2.06 version. An attacker, making use of the default credentials, could upload a backup file containing a symlink to /etc/shadow, allowing him to obtain the content of this path.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:generex:cs141_firmware:*:*:*:*:*:*:*:* 2.06 (excluding)
cpe:2.3:h:generex:cs141:-:*:*:*:*:*:*:*