SB2018120309 - Information disclosure in Zyxel VMG1312-B10D
Published: December 3, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Path traversal (CVE-ID: CVE-2018-19326)
The vulnerability allows a remote attacker to conduct directory traversal attack on the target system.
The vulnerability exists due to path traversal, as demonstrated by reading /etc/passwd. A remote unauthenticated attacker can send a specially crafted URL request containing "dot dot" sequences (/../), conduct directory traversal attack and view arbitrary files.
Remediation
Install update from vendor's website.