Executive brief
A directory traversal vulnerability exists in the EndRun Technologies Sonoma D12 Network Time Server, a device used to provide precise GPS-based timing to corporate networks. An attacker with low-level access can exploit this flaw to bypass security restrictions and read sensitive files stored on the device. This could lead to the exposure of configuration data or other internal information, potentially aiding further attacks against the network infrastructure.
Technical details
A directory traversal vulnerability (CWE-22) exists in the web management interface of the EndRun Technologies Sonoma D12 Network Time Server (GPS) running firmware versions 6010-0076-000 and 6010-0071-000 v4.00. The flaw stems from improper sanitization of user-supplied input used in file path construction. A remote attacker with low-privileged credentials can exploit this by submitting specially crafted requests containing path traversal sequences (e.g., ../) to access arbitrary files on the underlying filesystem. While the vendor has not yet released a formal firmware patch, they have provided a workaround to disable the web management service (httpd) to mitigate the risk.
Affected products
- EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 Ver 4.00, 6010-0071-000 v4.00
Timeline
- 2025-08-31: disclosed: Vulnerabilities discovered and reported to vendor by SDAIA PT Team.
- 2025-10-03: advisory: Security advisory published by researchers.
- 2025-10-06: other: CVE records published.