Impact
A path traversal vulnerability exists in the Log File Download Endpoint of wvp-GB28181-pro (version 2.7.4-20260107). By manipulating the fileName parameter in LogController.java, an attacker can traverse directory boundaries and access files outside the intended logging directory. The flaw can be triggered remotely via the exposed web endpoint, and a public exploit has already been released. Successful exploitation results in reading arbitrary files on the host, potentially exposing sensitive configuration data or credentials.
Affected Systems
The vulnerability affects the product wvp-GB28181-pro from vendor 648540858, specifically released version 2.7.4-20260107. No other version information is currently provided, so any deployment of this exact version is at risk.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, and the EPSS score is not available, so the current likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. Attackers can reach the vulnerable endpoint over the network and supply a crafted fileName value; based on the description, it is inferred that the path traversal is not constrained by authentication or other checks, making the exploitation straightforward for remote actors. Given the publicly available exploit code, the risk to systems that remain on the vulnerable version is significant, especially if the application is exposed to untrusted clients.
OpenCVE Enrichment