CVE-2019-13408

CVE-2019-13408: Advan VD-1 allows users to download arbitrary files

Vendor Androvideo
Product Advan VD-1 firmware
Weakness CWE-23
Published August 29, 2019
Last update September 17, 2024

CVSS base score

What the vulnerability does

01Description

A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download arbitrary files via url cgibin/ExportSettings.cgi?Download=filepath, without any authentication.

Key dates

02Disclosure timeline

August 29, 2019 CVE published
September 17, 2024 Record updated