WaveStore WaveView Client Path Traversal Vulnerability Allowing File Manipulation on WaveStore Server

Vulnerability

A path traversal vulnerability has been identified in the WaveView client, allowing high-privileged attackers to read or delete files on the connected WaveStore Server. This issue arises in the 'alog' script, where improper validation of file paths can be exploited to access or modify files with the permissions of the 'dvr' user. The vulnerability affects all versions of WaveStore Server prior to 6.44.44.

Impact

Exploitation of this vulnerability allows for unauthorized reading or deletion of files on the WaveStore Server, potentially leading to loss of critical data or disruption of services.

Remediation

Users can upgrade to WaveStore Server version 6.44.44 or later to address this vulnerability.

Added: Dec 16, 2025, 1:18 PM
Updated: Dec 16, 2025, 2:13 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
4.8
remediation
7.7
relevance
1.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.