CVE-2020-23161
EUVD-2020-1591426.01.2021, 18:15
Local file inclusion in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to traverse directories and read sensitive files via the Maintenance > Logs menu and manipulating the file-path in the URL.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| pyres | termod4_firmware | 𝑥 < 10.04k |
𝑥
= Vulnerable software versions
References