vendor:
Wifi HD Wireless Disk Drive
by:
Chokri Hammedi
7.5
CVSS
HIGH
Local File Inclusion
CWE
Product Name: Wifi HD Wireless Disk Drive
Affected Version From: 11
Affected Version To: 11
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: iPhone OS 15_5
2022
Wifi HD Wireless Disk Drive 11 – Local File Inclusion
The exploit allows an attacker to include local files on the server by manipulating the file path in the HTTP request. This can lead to unauthorized access to sensitive information or remote code execution.
Mitigation:
The vendor should sanitize user input and validate file paths to prevent directory traversal attacks. It is recommended to update to a patched version if available.