Home
MEDIUM: 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NDefault status
unaffected
0.0.0 (semver) before 6.0.1.0
affected
Default status
unaffected
0.0.0 (semver) before 6.0.1.0
affected
Default status
unaffected
0.0.0 (semver) before 6.0.1.0
affected
Description
A low‑privileged remote attacker can directly interact with the wwwdnload.cgi endpoint to download any resource available to administrators, including system backups and certificate request files.
Problem types
CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere
Product status
0.0.0 (semver) before 6.0.1.0
0.0.0 (semver) before 6.0.1.0
0.0.0 (semver) before 6.0.1.0
Credits
Adrien Rey from Cyber Defense Campus Zurich
Daniel Hulliger from Armasuisse
References
www.mbs-solutions.de/mbs-2025-0001