漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
A critical information disclosure vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters due to Incorrect Access Control (CWE-284). Unauthenticated attackers can directly access sensitive database backup files (snapshot_users.db) via publicly exposed URLs (/logs/devcfg/snapshot/ and /logs/devcfg/user/). Exploiting this vulnerability allows retrieval of sensitive user data, including login credentials, potentially leading to full system compromise.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GatesAir Maxiva 安全漏洞
Vulnerability Description
GatesAir Maxiva是美国GatesAir公司的一系列发射器。 GatesAir Maxiva UAXT、VAXT存在安全漏洞,该漏洞源于访问控制不正确,导致基于Web的管理界面中存在严重信息泄露漏洞。未经身份验证的攻击者可以通过公开的URL直接访问敏感数据库备份文件。
CVSS Information
N/A
Vulnerability Type
N/A