Description
An authorized remote attacker can access files and directories outside the intended web root, potentially exposing sensitive system information of the affected Sunny Boy devices.
Problem types
CWE-23 Relative Path Traversal
Product status
0.0.0 before 3.10.27.R
0.0.0 before 3.10.27.R
0.0.0 before 3.10.27.R
0.0.0 before 3.10.27.R
0.0.0 before 3.10.27.R
Credits
Ahmed Alroky from KOIN Network
References
certvde.com/en/advisories/VDE-2025-066