Directory Traversal Vulnerability in MERCUSYS Mercury X18G Devices
CVE-2021-23242
5.3MEDIUM
What is CVE-2021-23242?
The MERCUSYS Mercury X18G devices version 1.0.5 are susceptible to a directory traversal vulnerability that permits unauthorized access to filesystem directories. By exploiting this vulnerability, an attacker could manipulate the UPnP server to retrieve sensitive configuration files, including '/../../conf/template/uhttpd.json', potentially exposing critical system information and leading to other security risks.