216.73.216.6

CVE-2019-25610

· Published 22/03/2026 14:16 · Modified 23/03/2026 14:31

Labels: CVE-2019-25610 2026-03-22CVE-2019-25610CWE-22[email protected]

Essential information

Published
22/03/2026 14:16
Modified
23/03/2026 14:31
Author
Creator
CVSS
7.1 HIGH (v3) 7.1 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

NetNumber Titan Master 7.9.1 contains a path traversal vulnerability in the drp endpoint that allows authenticated users to download arbitrary files by injecting directory traversal sequences. Attackers can manipulate the path parameter with base64-encoded payloads containing ../ sequences to bypass authorization and retrieve sensitive system files like /etc/shadow.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
netnumber / titan master cpe:2.3:a:netnumber:titan_master:7.9.1:*:*:*:*:*:*:*

References