We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-27718



Description

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file upload process of the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, the product's files may be obtained and/or altered or arbitrary code may be executed by a crafted HTTP request to specific functions of the product from a device connected to the LAN side.

Reserved 2025-03-11 | Published 2025-03-28 | Updated 2025-03-28 | Assigner jpcert


HIGH: 8.8CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

Improper limitation of a pathname to a restricted directory ('Path Traversal')

Product status

Ver 002.002.003 and earlier
affected

References

kddi-tech.com/contents/appendix_L2_06.html

jvn.jp/en/jp/JVN04278547/

cve.org (CVE-2025-27718)

nvd.nist.gov (CVE-2025-27718)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-27718

Support options

Helpdesk Chat, Email, Knowledgebase