ZeroHour

CVE-2024-40088

CVSS 3.1
5.3 medium
EPSS
<1%p51
Published
()
Modified
Description

A Directory Traversal vulnerability in the Boa webserver of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers to enumerate the existence and length of any file in the filesystem by placing malicious payloads in the path of any HTTP request.

Vendors
viloliving
Products
vilo 5 firmware
Weakness
CWE-79, CWE-116
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.