cve/2025/CVE-2025-47423.md
2025-09-29 21:09:30 +02:00

948 B

CVE-2025-47423

Description

Personal Weather Station Dashboard 12_lts allows unauthenticated remote attackers to read arbitrary files via ../ directory traversal in the test parameter to /others/_test.php, as demonstrated by reading the server's private SSL key in cleartext.

POC

Reference

Github