Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Karl W

Researcher fromArqiva Threat Team
#26068of 56,337
9.8Total CVSS
Vulnerabilities · 1
PT-2018-18143
9.8
2018-04-17
Appear Tv · Appear Tv Xc5100 · CVE-2018-7539
**Name of the Vulnerable Software and Affected Versions** Appear TV XC5000 and XC5100 devices with firmware 3.26.217 **Description** The issue allows an attacker to read OS files by sending a specially crafted HTTP request, such as GET /../../../../../../../../../../../../etc/passwd, to the web server (fuzzd/0.1.1) running the Maintenance Center on port TCP/8088. This can potentially lead to full compromise of the device. **Recommendations** For Appear TV XC5000 and XC5100 devices with firmware 3.26.217, consider restricting access to the Maintenance Center on port TCP/8088 as a temporary workaround until a patch is available. Avoid using the web server to access sensitive OS files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.