CVE-2021-44124
Last modified
CVE-2021-44124 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Hiby Music Hiby OS R3 Pro 1.5 and 1.6 is vulnerable to Directory Traversal. The HTTP Server does not have enough input data sanitization when shown data from SD Card, an attacker can navigate through the device's File System over HTTP.. EPSS estimates a 1.86% chance of exploitation in the next 30 days.
Description
Hiby Music Hiby OS R3 Pro 1.5 and 1.6 is vulnerable to Directory Traversal. The HTTP Server does not have enough input data sanitization when shown data from SD Card, an attacker can navigate through the device's File System over HTTP.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hiby | R3 Pro Firmware | 1.5 |
| Hiby | R3 Pro Firmware | 1.6 |
References
- https://github.com/feric/Findings/tree/main/Hiby/Web%20Server/Path%20TraversalExploit, Third Party Advisory
- https://github.com/vext01/hiby-issues/issues/9#issuecomment-907891626Exploit, Third Party Advisory
- https://github.com/feric/Findings/tree/main/Hiby/Web%20Server/Path%20TraversalExploit, Third Party Advisory
- https://github.com/vext01/hiby-issues/issues/9#issuecomment-907891626Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-44124?
How severe is CVE-2021-44124?
How do I fix CVE-2021-44124?
Are you affected by CVE-2021-44124?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
