Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-01601
HistoryNov 21, 2021 - 12:00 a.m.

Lantronix PremierWave 2050 Path Traversal Vulnerability

2021-11-2100:00:00
China National Vulnerability Database
www.cnvd.org.cn
8
lantronix premierwave 2050
embedded wi-fi module
security vulnerability
web manager
fsbrowseclean feature
filter bypass
arbitrary file deletion
authenticated attacker
http request
version 8.9.0.0r4
lantronix inc.
cnvd

EPSS

0.001

Percentile

39.7%

The Lantronix PremierWave 2050 is an embedded enterprise Wi-Fi module from Lantronix, Inc. The Lantronix PremierWave 2050 in version 8.9.0.0R4 contains a security vulnerability that stems from the Web Manager FsBrowseClean feature failing to properly filter special elements in resource or file paths. An authenticated attacker could use this vulnerability to potentially cause arbitrary file deletion through a carefully constructed HTTP request.

EPSS

0.001

Percentile

39.7%

Related for CNVD-2022-01601