Executive brief
PCViewer vt1000, a file management and viewing application, contains a security flaw that allows unauthorized individuals to access files on the host system. By sending a specially crafted web request, an attacker can bypass security restrictions to read sensitive system files, such as configuration data or password files. This could lead to a complete compromise of the device's data and further unauthorized access to the network.
Technical details
A directory traversal vulnerability (CWE-22) exists in the PCViewer vt1000 web interface. The application fails to properly sanitize input in HTTP GET requests, allowing an unauthenticated remote attacker to use dot-dot-slash (../) sequences to escape the intended web root directory. By exploiting this flaw, an attacker can read arbitrary files on the underlying operating system, such as /etc/passwd or sensitive configuration files. The vulnerability was verified using a proof-of-concept request targeting the Cross Web Server component of the device.
Affected products
- PCViewer vt1000 vt1000 and earlier
Timeline
- 2018-07-21: disclosed: Vulnerability discovered by researcher
- 2018-08-23: other: Exploit published on Exploit-DB
- 2026-05-25: advisory: CVE record published/updated by VulnCheck and NVD