TG8 Firewall exposes a directory such as /data/ over HTTP without authentication. This directory stores credential files for previously logged-in users. A remote unauthenticated attacker can enumerate and download files within the directory to obtain valid account usernames and passwords, leading to loss of confidentiality and further unauthorized access.
CVSS
No CVSS.
References
Configurations
No configuration.
History
17 Nov 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://ssd-disclosure.com/ssd-advisory-tg8-firewall-preauth-rce-and-password-disclosure/ - |
14 Nov 2025, 23:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-14 23:15
Updated : 2025-11-18 14:06
NVD link : CVE-2021-4471
Mitre link : CVE-2021-4471
CVE.ORG link : CVE-2021-4471
JSON object : View
Products Affected
No product.
CWE
CWE-538
Insertion of Sensitive Information into Externally-Accessible File or Directory
