QID 731246
Date Published: 2024-03-26
QID 731246: TVT NVMS-1000 Directory Traversal Vulnerability
CVE-2019-20085: TVT NVMS-1000 devices are vulnerable to directory traversal vulnerability.
Affected Versions:
TVT NVMS-1000
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable installation of TVT NVMS-1000 by sending a crafted payload as an HTTP GET request. The payload tries to read files such as 'win.ini' or '/etc/passwd' to check for the vulnerability.
Successful exploitation of this vulnerability may allow an unauthenticated remote attacker to read arbitrary file from the target system.
Solution
Customers are advised to check with TVT Vendor for more information about the latest version and information to mitigate this vulnerability.
Vendor References
- TVT Vendor Homepage -
en.tvt.net.cn/
CVEs related to QID 731246
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| TVT Homepage |
|