Executive brief
TVT NVMS-1000 devices are vulnerable to a directory traversal attack via specially crafted GET requests. An unauthenticated remote attacker can exploit this to access sensitive files on the underlying file system by using dot-dot-slash (../) sequences.
Affected products
- TVT NVMS-1000 All versions prior to patch
Timeline
- 2019-12-29: disclosed: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: advisory