Path traversal in Zyxel VMG1312-B10D - CVE-2018-19326
Published: December 3, 2018 / Updated: December 3, 2018
Zyxel VMG1312-B10D
Detailed vulnerability description
The vulnerability allows a remote attacker to conduct directory traversal attack on the target system.
The vulnerability exists due to path traversal, as demonstrated by reading /etc/passwd. A remote unauthenticated attacker can send a specially crafted URL request containing "dot dot" sequences (/../), conduct directory traversal attack and view arbitrary files.