LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
http://seclists.org/fulldisclosure/2019/Apr/12 | mailing list exploit third party advisory |
http://packetstormsecurity.com/files/152453/Loytec-LGATE-902-XSS-Traversal-File-Deletion.html | exploit vdb entry third party advisory |
https://seclists.org/fulldisclosure/2019/Apr/12 | mailing list exploit third party advisory |