CVE-2025-27932

CVSS 3.0 Score 8.1 of 10 (high)

Details

Published Mar 28, 2025
CWE ID 22

Summary

CVE-2025-27932 is a path traversal vulnerability affecting the USB storage file-sharing function of HGW-BL1500HM versions 002.002.003 and earlier. This issue allows an attacker to bypass restrictions and delete files or cause a denial of service condition on the device. The file deletion process does not properly limit the pathname, creating an opportunity for malicious actors to manipulate the system and potentially disrupt its functionality.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share