Arbitrary File Download Vulnerability in beroNet VoIP Gateways (CVE-2021-XXXX)

Arbitrary File Download Vulnerability in beroNet VoIP Gateways (CVE-2021-XXXX)

CVE-2017-18923 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

beroNet VoIP Gateways before 3.0.16 have a PHP script that allows downloading arbitrary files, including ones with credentials.

Learn more about our Web Application Penetration Testing UK.