Junglewise Threat Intelligence

CVE-2019-20085: TVT NVMS-1000 Directory Traversal Vulnerability

CVE-2019-20085 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2021-11-03

Executive brief

TVT NVMS-1000 devices are vulnerable to a directory traversal attack via specially crafted GET requests. An unauthenticated remote attacker can exploit this to access sensitive files on the underlying file system by using dot-dot-slash (../) sequences.

Affected products

  • TVT NVMS-1000 All versions prior to patch

Timeline

  • 2019-12-29: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: advisory