KDDI HGW-BL1500HM Path Traversal Vulnerability in USB File Upload Function
Vulnerability
A path traversal vulnerability has been identified in the file upload process of the USB storage file-sharing function on the KDDI HGW-BL1500HM home gateway, all versions through 002.002.003. This vulnerability allows an attacker to access and potentially modify the device's files or execute arbitrary code by sending a crafted HTTP request to specific functions of the product from a device connected to the LAN.
Impact
Exploitation of this vulnerability could lead to unauthorized access to the device's files, allowing them to be viewed or modified. Additionally, it could enable the execution of arbitrary code on the device.
Remediation
Users are advised to update the firmware to the latest version. The device automatically communicates with KDDI's central system to download and install new firmware updates, maintaining it in an optimal state. No user action is required, but the device should be connected to the internet and powered on.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
