CVE-2025-27726

Published Mar 28, 2025

Last updated 8 days ago

Overview

Description
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file download process of the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, the product's files may be obtained and/or altered by a crafted HTTP request to specific functions of the product from a device connected to the LAN side.
Source
vultures@jpcert.or.jp
NVD status
Awaiting Analysis

Risk scores

CVSS 3.0

Type
Secondary
Base score
2.1
Impact score
1.4
Exploitability score
0.7
Vector string
CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity
LOW

Weaknesses

vultures@jpcert.or.jp
CWE-22

Social media

Hype score
Not currently trending