MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') may allow Unauthenticated RCE
The vulnerability is based on improper limitation of a pathname to a restricted directory. An attacker can craft a network request containing path traversal sequences (e.g., '../') to escape the allowed filesystem area and gain access to sensitive resources or execute arbitrary code. The attack requires no authentication or user interaction and is possible remotely over the network.
An attacker can gain complete control over the vulnerable system by executing arbitrary code remotely (RCE), and can also gain unauthorized access to sensitive data, modify it, or cause service unavailability.
Patches available from the manufacturer should be applied according to the references. Due to the lack of authentication requirement, it is also recommended to restrict network access to the DeviceHub interface only to trusted IP addresses until the update is deployed.
MileSight DeviceHub — versions indicated in the manufacturer's references
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCanonical Ubuntu
OSCanonical20.04Milesight Devicehub
APPMilesight3.0.1-r1
Related vulnerabilities
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
Redis – ucieczka z Lua sandbox umożliwiająca zdalne wykonanie kodu (RCE)
SaltStack Salt: nieautoryzowany dostęp do metod salt-master umożliwiający RCE
RCE jako root w OpenSMTPD przez command injection w polu MAIL FROM
RCE w Exim — heap-based buffer overflow w obsłudze komendy EHLO