Description
NetNumber Titan Master 7.9.1 contains a path traversal vulnerability in the drp endpoint that allows authenticated users to download arbitrary files by injecting directory traversal sequences. Attackers can manipulate the path parameter with base64-encoded payloads containing ../ sequences to bypass authorization and retrieve sensitive system files like /etc/shadow.
Problem types
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Credits
MobileNetworkSecurity
References
www.exploit-db.com/exploits/46811 (ExploitDB-46811)
www.netnumber.com/products/ (Official Product Homepage)
www.vulncheck.com/...ber-titan-master-path-traversal-via-drp (VulnCheck Advisory: NetNumber Titan Master 7.9.1 Path Traversal via drp)