Description
DBLTek GoIP-1 firmware versions up to and including GHSFVT-1.1-67-5 contain a local file inclusion vulnerability. The device's web server exposes handlers (`frame.html` and `frame.A100.html`) that accept a path parameter (`content` or `sidebar`) which is not properly validated or canonicalized. An attacker can supply directory-traversal sequences to cause the server to read and return arbitrary filesystem files that the webserver user can access. Other GoIP models and firmware versions are likely affected. Exploitation evidence was observed by the Shadowserver Foundation on 2024-03-21 UTC.
INFO
Published Date :
2025-11-12T22:10:11.204Z
Last Modified :
2025-11-13T14:35:36.484Z
Source :
VulnCheck
AFFECTED PRODUCTS
The following products are affected by CVE-2022-4982 vulnerability.
| Vendors | Products |
|---|---|
| Dbltek |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2022-4982.