Vulnerabilities > CVE-2022-45227 - Files or Directories Accessible to External Parties vulnerability in Dragino Lg01 Lora Firmware 4.3.4

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
dragino
CWE-552

Summary

The web portal of Dragino Lora LG01 18ed40 IoT v4.3.4 has the directory listing at the URL https://10.10.20.74/lib/. This address has a backup file which can be downloaded without any authentication.

Vulnerable Configurations

Part Description Count
OS
Dragino
1
Hardware
Dragino
1