DIAView (v4.2.0 and prior) - Directory Traversal Information Disclosure Vulnerability
The vulnerability results from improper handling of file paths — the application does not properly filter parent directory sequences (e.g., '../'), which allows an attacker to escape from the allowed working directory. An attacker can use a crafted network request to access any file in the server's file system. The lack of authentication requirement (PR:N, UI:N) makes it possible to conduct the attack remotely without any credentials.
An attacker can read confidential files from the host system on which DIAView runs, which may lead to disclosure of configuration data, credentials, or other sensitive information. According to the CVSS vector, the vulnerability provides high impact on the confidentiality, integrity, and availability of system resources.
Security patches available from the manufacturer should be applied in accordance with the references — details in the Delta Electronics security bulletin: Delta-PCSA-2025-00010 available at the address indicated in the references.
Delta Electronics DIAView in version 4.2.0 and all earlier versions.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X