NetNumber Titan Master 7.9.1 contains a path traversal vulnerability in the drp endpoint that allows authenticated users to download arbitrary files by injecting directory traversal sequences. Attackers can manipulate the path parameter with base64-encoded payloads containing ../ sequences to bypass authorization and retrieve sensitive system files like /etc/shadow.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-03-22 14:16
Updated : 2026-03-23 14:31
NVD link : CVE-2019-25610
Mitre link : CVE-2019-25610
CVE.ORG link : CVE-2019-25610
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
