CVE-2025-47423

Personal Weather Station Dashboard 12_lts allows unauthenticated remote attackers to read arbitrary files via ../ directory traversal in the test parameter to /others/_test.php, as demonstrated by reading the server's private SSL key in cleartext.
Configurations

No configuration.

History

08 May 2025, 14:39

Type Values Removed Values Added
Summary
  • (es) Personal Weather Station Dashboard 12_lts permite a atacantes remotos no autenticados leer archivos arbitrarios a través del directory traversal ../ en el parámetro de prueba a /others/_test.php, como se demuestra al leer la clave SSL privada del servidor en texto plano.

07 May 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-07 18:15

Updated : 2025-05-08 14:39


NVD link : CVE-2025-47423

Mitre link : CVE-2025-47423

CVE.ORG link : CVE-2025-47423


JSON object : View

Products Affected

No product.

CWE
CWE-24

Path Traversal: '../filedir'