Impact
The vulnerability in Zettlab D6 Ultra allows an attacker to use path traversal characters in a Docker compose file to mount host files such as /etc/passwd and /etc/shadow into a:/h_etc:rw, the attacker can read the host system’s credential files, exposing user account names and password hashes. This constitutes sensitive information disclosure that could aid credential cracking or privilege escalation if the hashed passwords are weak.
Affected Systems
This issue affects the Zettlab D6 Ultra device running firmware versions prior to 1.7.0. No other models or services from Zettlab are listed as vulnerable. The flaw exists in the compose file handler responsible for processing volume mounts.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. The EPSS score is <1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation. The attack vector is inferred to be local or dependent on the ability to provide or modify a compose file; if the device accepts externally supplied compose definitions, a remote attacker could create a maliciouswd and /etc/shadow. The exploit requires no additional privileges beyond the ability to run or submit the Compose configuration, so the risk escalates where untrusted users can influence container definitions.
OpenCVE Enrichment