DataTaker DT80 dEX 1.50.012 is susceptible to information disclosure. A remote attacker can obtain sensitive credential and configuration information via a direct request for the /services/getFile.cmd?userfile=config.xml URI, thereby possibly accessing sensitive information, modifying data, and/or executing unauthorized operations.
id: CVE-2017-11165
info:
name: DataTaker DT80 dEX 1.50.012 - Information Disclosure
author: the
...