QID 591356
Date Published: 2023-04-03
QID 591356: Lantronix PremierWave 2050 Web Manager FsMove directory traversal Vulnerability (TALOS-2021-1329)
AFFECTED PRODUCTS
Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU)
QID Detection Logic:
This QID checks for the Vulnerable version of Lantronix PremierWave 2050 using passive scanning
A directory traversal vulnerability exists in the Web Manager FsMove functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially crafted HTTP request can lead to local file inclusion. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Solution
Customers are advised to refer to CERT MITIGATIONS section TALOS-2021-1329 for affected packages and patching details.
Vendor References
- TALOS-2021-1329 -
talosintelligence.com/vulnerability_reports/TALOS-2021-1329
CVEs related to QID 591356
Software Advisories
| Advisory ID | Software | Component | Link |
|---|