vendor:
VelotiSmart Wifi
by:
Miguel Mendez Z
9.8
CVSS
CRITICAL
Directory Traversal
Unknown
CWE
Product Name: VelotiSmart Wifi
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2018-14064
CPE: Unknown
Tags: edb,cve,cve2018,lfi,camera,iot
CVSS Metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Nuclei Metadata: {'max-request': 1, 'vendor': 'velotismart_project', 'product': 'velotismart_wifi_firmware'}
Platforms Tested: Unix
2018
Vulnerability in VelotiSmart Wifi – Directory Traversal
The vulnerability that affects the device is LFI type in the uc-http service 1.0.0. It allows obtaining information of configurations, wireless scanned networks, sensitive directories, etc. of the device.
Mitigation:
Unknown