DBLTek GoIP-1 vGHSFVT-1.1-67-5 Unauthenticated LFI
Vulnerability Description
DBLTek GoIP-1 firmware versions up to and including GHSFVT-1.1-67-5 contain a local file inclusion vulnerability. The device's web server exposes handlers (`frame.html` and `frame.A100.html`) that accept a path parameter (`content` or `sidebar`) which is not properly validated or canonicalized. An attacker can supply directory-traversal sequences to cause the server to read and return arbitrary filesystem files that the webserver user can access. Other GoIP models and firmware versions are likely affected. Exploitation evidence was observed by the Shadowserver Foundation on 2024-03-21 UTC.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-4982
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Valtteri Lehtinen
- Lassi Korhonen
References
More from DBL Technology (DBLTek)
View All →Affected Vendor
DBL Technology (DBLTek)
View all reports →