CVE-2025-27716

CVSS 3.0 Score 6.5 of 10 (medium)

Details

Published Mar 28, 2025
CWE ID 22

Summary

CVE-2025-27716 is a path traversal vulnerability affecting the file/folder listing process of HGW-BL1500HM USB storage file-sharing functions with versions 002.002.003 and earlier. This issue allows an attacker to access and potentially modify files on the product through a crafted HTTP request to specific functions, by traversing outside the restricted directory. Exploitation of this vulnerability could lead to unauthorized file access and manipulation on the LAN-connected device.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share