CVE-2024-13991
15.10.2025, 02:15
Huijietong Cloud Video Platform contains a path traversal vulnerability that allows an unauthenticated attacker can supply arbitrary file paths to the `fullPath` parameter of the `/fileDownload?action=downloadBackupFile` endpoint and retrieve files from the server filesystem.VulnCheck has observed this vulnerability being targeted by the RondoDox botnet campaign.
Awaiting analysis
This vulnerability is currently awaiting analysis.