CVE-2021-44124
Summary
| CVE | CVE-2021-44124 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-28 16:15:00 UTC |
| Updated | 2022-04-04 17:32:00 UTC |
| Description | Hiby Music Hiby OS R3 Pro 1.5 and 1.6 is vulnerable to Directory Traversal. The HTTP Server does not have enough input data sanitization when shown data from SD Card, an attacker can navigate through the device's File System over HTTP. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Hiby | R3 Pro | - | All | All | All |
| Operating System | Hiby | R3 Pro Firmware | 1.5 | All | All | All |
| Operating System | Hiby | R3 Pro Firmware | 1.6 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Findings/Hiby/Web Server/Path Traversal at main · feric/Findings · GitHub | MISC | github.com | |
| Path traversal vulnerability in web server. · Issue #9 · vext01/hiby-issues · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.