QID 591357
Date Published: 2023-04-03
QID 591357: Lantronix PremierWave 2050 Web Manager FsMove directory traversal Vulnerability (TALOS-2021-1338)
AFFECTED PRODUCTS
Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU)
QID Detection Logic:
This QID checks for the Vulnerable version of Lantronix PremierWave 2050 using passive scanning
A directory traversal vulnerability exists in the Web Manager FsMove functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially crafted HTTP request can lead to local file inclusion. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Solution
Customers are advised to refer to CERT MITIGATIONS section TALOS-2021-1338 for affected packages and patching details.
Vendor References
- TALOS-2021-1338 -
talosintelligence.com/vulnerability_reports/TALOS-2021-1338
CVEs related to QID 591357
Software Advisories
| Advisory ID | Software | Component | Link |
|---|