Path Traversal vulnerability in WF Steuerungstechnik GmbH airleader MASTER allows Retrieve Embedded Sensitive Data.This issue affects airleader MASTER: 3.0046.
The vulnerability results from improper file path handling (CWE-35 — path traversal), which allows an attacker to escape the allowed directory by manipulating file references containing sequences such as '../'. The attack does not require authentication, user interaction, or special network conditions — network access to the vulnerable device is sufficient. As a result, it is possible to read embedded sensitive data stored in the system.
An attacker can gain access to sensitive data stored on the device without authentication, and in case of data breach from related systems — consequences may also include external environments.
Patches available from the manufacturer should be applied according to the references. It is also recommended to restrict network access to the device only to trusted hosts and to monitor unauthorized access attempts to system resources.
WF Steuerungstechnik GmbH airleader MASTER version 3.0046
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X