An unauthenticated directory traversal vulnerability in cgi-bin/upload.cgi in SNMP Web Pro 1.1 allows a remote attacker to read arbitrary files. The CGI concatenates the user-supplied params directly onto the base path (/var/www/files/userScript/) using memcpy + strcat without validation or canonicalization, enabling ../ sequences to escape the intended directory. The download branch also echoes the unsanitized params into Content-Disposition, introducing header-injection risk.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://damiri.fr/en/cve/CVE-2025-65287 |
|
History
Wed, 10 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| Metrics |
cvssV3_1
|
Wed, 10 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Voltronicpower
Voltronicpower snmp Web Pro |
|
| Vendors & Products |
Voltronicpower
Voltronicpower snmp Web Pro |
Tue, 09 Dec 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated directory traversal vulnerability in cgi-bin/upload.cgi in SNMP Web Pro 1.1 allows a remote attacker to read arbitrary files. The CGI concatenates the user-supplied params directly onto the base path (/var/www/files/userScript/) using memcpy + strcat without validation or canonicalization, enabling ../ sequences to escape the intended directory. The download branch also echoes the unsanitized params into Content-Disposition, introducing header-injection risk. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-12-09T00:00:00.000Z
Updated: 2025-12-10T21:03:00.912Z
Reserved: 2025-11-18T00:00:00.000Z
Link: CVE-2025-65287
Updated: 2025-12-10T21:02:57.601Z
Status : Awaiting Analysis
Published: 2025-12-09T16:18:17.633
Modified: 2025-12-10T21:16:06.677
Link: CVE-2025-65287
No data.