CVE-2021-4471

TG8 Firewall exposes a directory such as /data/ over HTTP without authentication. This directory stores credential files for previously logged-in users. A remote unauthenticated attacker can enumerate and download files within the directory to obtain valid account usernames and passwords, leading to loss of confidentiality and further unauthorized access.
CVSS

No CVSS.

Configurations

No configuration.

History

17 Nov 2025, 21:15

Type Values Removed Values Added
References () https://ssd-disclosure.com/ssd-advisory-tg8-firewall-preauth-rce-and-password-disclosure/ - () https://ssd-disclosure.com/ssd-advisory-tg8-firewall-preauth-rce-and-password-disclosure/ -

14 Nov 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-14 23:15

Updated : 2025-11-18 14:06


NVD link : CVE-2021-4471

Mitre link : CVE-2021-4471

CVE.ORG link : CVE-2021-4471


JSON object : View

Products Affected

No product.

CWE
CWE-538

Insertion of Sensitive Information into Externally-Accessible File or Directory