CVE-2025-27726
CVSS 3.0 Score 2.1 of 10 (low)
Details
Summary
CVE-2025-27726 is a path traversal vulnerability affecting the USB storage file-sharing function of HGW-BL1500HM versions 002.002.003 and earlier. This issue allows an attacker to obtain or alter the product's files by crafting a malicious HTTP request to specific functions on the LAN side. The vulnerability arises due to an improper limitation of the pathname to a restricted directory. Successful exploitation can pose significant risks, including unauthorized access or modification of sensitive information. Users are recommended to update their HGW-BL1500HM firmware to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.