// For flags

CVE-2019-13408

Advan VD-1 allows users to download arbitrary files

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download arbitrary files via url cgibin/ExportSettings.cgi?Download=filepath, without any authentication.

Una vulnerabilidad de recorrido de ruta relativa encontrada en las versiones de firmware de Advan VD-1 hasta 230. Permite a los atacantes descargar archivos arbitrarios a través de url cgibin/ExportSettings.cgi? Ruta de descarga de archivos, sin ninguna autenticación.

*Credits: Keniver Wang (CHT Security)
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-07-08 CVE Reserved
  • 2019-08-29 CVE Published
  • 2024-09-17 CVE Updated
  • 2024-09-17 First Exploit
  • 2024-12-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
  • CWE-23: Relative Path Traversal
  • CWE-862: Missing Authorization
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Androvideo
Search vendor "Androvideo"
Vd 1 Firmware
Search vendor "Androvideo" for product "Vd 1 Firmware"
<= 230
Search vendor "Androvideo" for product "Vd 1 Firmware" and version " <= 230"
-
Affected
in Androvideo
Search vendor "Androvideo"
Vd 1
Search vendor "Androvideo" for product "Vd 1"
--
Safe
Geovision
Search vendor "Geovision"
Gv-vr360 Firmware
Search vendor "Geovision" for product "Gv-vr360 Firmware"
<= 1.10
Search vendor "Geovision" for product "Gv-vr360 Firmware" and version " <= 1.10"
-
Affected
in Geovision
Search vendor "Geovision"
Gv-vr360
Search vendor "Geovision" for product "Gv-vr360"
--
Safe
Geovision
Search vendor "Geovision"
Gv-vd8700 Firmware
Search vendor "Geovision" for product "Gv-vd8700 Firmware"
<= 1.01
Search vendor "Geovision" for product "Gv-vd8700 Firmware" and version " <= 1.01"
-
Affected
in Geovision
Search vendor "Geovision"
Gv-vd8700
Search vendor "Geovision" for product "Gv-vd8700"
--
Safe