CVE-2019-7404

An issue was discovered on LG GAMP-7100, GAPM-7200, and GAPM-8000 routers. An unauthenticated user can read a log file via an HTTP request containing its full pathname, such as http://192.168.0.1/var/gapm7100_${today's_date}.log for reading a filename such as gapm7100_190101.log.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:lg:gamp-7100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lg:gamp-7100:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:lg:gapm-7200_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lg:gapm-7200:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:lg:gapm-8000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lg:gapm-8000:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-05-13 14:29

Updated : 2024-02-04 20:20


NVD link : CVE-2019-7404

Mitre link : CVE-2019-7404

CVE.ORG link : CVE-2019-7404


JSON object : View

Products Affected

lg

  • gamp-7100
  • gamp-7100_firmware
  • gapm-8000
  • gapm-7200_firmware
  • gapm-8000_firmware
  • gapm-7200
CWE
CWE-306

Missing Authentication for Critical Function