MEDIUM
Personal Weather Station Dashboard 12_lts allows unauthenticated remote attackers to read arbitrary files via ../ directory traversal in the test parameter to /others/_test.php, as demonstrated by reading the server's private SSL key in cleartext
Published May 7, 2025
5.8
MEDIUMCVSS 3.1
EPSS 1.98%
Description
Affected products
Remediation
References (3)
Change history (0)
No recorded changes yet.