Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-01589
HistoryDec 27, 2021 - 12:00 a.m.

Lantronix PremierWave 2050 Path Traversal Vulnerability (CNVD-2022-01589)

2021-12-2700:00:00
China National Vulnerability Database
www.cnvd.org.cn
11
lantronix premierwave 2050
embedded enterprise wi-fi module
path traversal vulnerability
directory access
web manager
fstftp feature
authenticated http request
overwrite file

EPSS

0.001

Percentile

45.0%

The Lantronix PremierWave 2050 is an embedded enterprise Wi-Fi module from Lantronix, Inc. A path traversal vulnerability exists in the Lantronix PremierWave 2050, which stems from a lack of effective restriction and filtering of directory access by the software-focused Web Manager FsTFtp feature. An attacker could exploit the vulnerability by initiating an authenticated HTTP request to overwrite the FsTFtp file with an arbitrary file.

EPSS

0.001

Percentile

45.0%

Related for CNVD-2022-01589