Home

Description

An unauthenticated remote attacker can bypass authentication by exploiting insufficient URI validation and using path traversal sequences (e.g., /js/../cgi-bin/post.cgi), gaining unauthorized access to protected CGI endpoints and configuration downloads.

PUBLISHED Reserved 2026-01-13 | Published 2026-02-09 | Updated 2026-02-09 | Assigner CERTVDE




HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Problem types

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Product status

Default status
unaffected

0.0.0 (semver)
affected

Default status
unaffected

0.0.0 (semver)
affected

Default status
unaffected

2.64
affected

Default status
unaffected

2.64
affected

Credits

Diconium finder

References

certvde.com/de/advisories/VDE-2026-004

cve.org (CVE-2026-22905)

nvd.nist.gov (CVE-2026-22905)

Download JSON