"TITLE":"Advan VD-1 allows users to download arbitrary files"
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"AndroVideo",
"product":{
"product_data":[
{
"product_name":"Advan VD-1 firmware",
"version":{
"version_data":[
{
"version_value":"up to 230"
}
]
}
}
]
}
}
]
}
},
"credit":[
{
"lang":"eng",
"value":"Keniver Wang (CHT Security) "
}
],
"data_format":"MITRE",
"data_type":"CVE",
"data_version":"4.0",
"description":{
"description_data":[
{
"lang":"eng",
"value":"A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download arbitrary files via url cgibin/ExportSettings.cgi?Download=filepath, without any authentication."