Longjing Technology BEMS API versions up to and including 1.21 contains an unauthenticated arbitrary file download vulnerability in the 'downloads' endpoint. The 'fileName' parameter is not properly sanitized, allowing attackers to craft traversal sequences and access sensitive files outside the intended directory.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Nov 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Shenzhen Longjing Technology
Shenzhen Longjing Technology bems Api |
|
| Vendors & Products |
Shenzhen Longjing Technology
Shenzhen Longjing Technology bems Api |
Wed, 12 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Longjing Technology BEMS API versions up to and including 1.21 contains an unauthenticated arbitrary file download vulnerability in the 'downloads' endpoint. The 'fileName' parameter is not properly sanitized, allowing attackers to craft traversal sequences and access sensitive files outside the intended directory. | |
| Title | Longjing Technology BEMS API <= 1.21 Remote Arbitrary File Download | |
| Weaknesses | CWE-22 CWE-552 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-11-12T22:07:30.512Z
Updated: 2025-11-13T17:05:15.434Z
Reserved: 2025-11-12T20:55:39.039Z
Link: CVE-2021-4463
Updated: 2025-11-13T17:05:11.413Z
Status : Received
Published: 2025-11-12T22:15:41.863
Modified: 2025-11-12T22:15:41.863
Link: CVE-2021-4463
No data.
ReportizFlow