Description
A path traversal vulnerability in Novakon P series allows to expose the root file system "/" and modify all files with root permissions. This way the system can also be compromized.This issue affects P series: P – V2001.A.C518o2.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
P – V2001.A.c518o2 (custom)
Credits
S. Dietz (CyberDanube)
References
seclists.org/fulldisclosure/2025/Sep/70
cyberdanube.com/...le-vulnerabilities-in-novakon-hmi-series/