go to Content

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center


Smart eVision - Path Traversal -1

TVN ID TVN-202209006
CVE ID CVE-2022-39033
CVSS 9.8 (Critical)
Affected Products Smart eVision ver.2022.02.21
Description Smart eVision’s file acquisition function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication, access restricted paths to download and delete arbitrary system files to disrupt service.
Solution Update Smart eVision version to 2022.06.16
Credit Gary Tan, Zac Wang (Talent-Jump)
Public Date 2022-09-28