Impact
An unauthenticated path traversal flaw in the web management interface of Wireless Technology, Inc. devices allows an attacker to craft HTTP requests with traversal sequences such as "../". When these requests reach the firmware, the device resolves the sequences and reads files located outside the intended web root directory, potentially exposing sensitive system files, configuration data, or credentials. The weakness is classified as CWE‑22 and directly undermines the confidentiality of the device’s data.
Affected Systems
Wireless Technology, Inc. devices running firmware version 3.5.0.r released 2024/05/24 are affected. The vulnerability exists in the web management interface component of the firmware.
Risk and Exploitability
The CVSS score of 7.5 categorizes the issue as high severity, reflecting significant risk if exploited. Because no authentication is required, an attacker can launch the exploit from any network that can reach the management interface. The EPSS score of less than 1% and the fact that the vulnerability is not listed in the CISA KEV catalog suggest a relatively low baseline likelihood of exploitation, yet the simple attack path and high potential impact support a strong remediation stance.
OpenCVE Enrichment