CVE-2021-26725
Path Traversal vulnerability when changing timezone using web GUI of Nozomi Networks Guardian, CMC allows an authenticated administrator to read-protected system files. This issue affects: Nozomi Networks Guardian 20.0.7.3 version 20.0.7.3 and prior versions. Nozomi Networks CMC 20.0.7.3 version 20.0.7.3 and prior versions.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.53%
- CWE
- CWE-24
- Published
- 2021-02-22
- Last modified
- 2026-03-13
Affected products
- Nozomi Networks Guardian
- Nozomi Networks CMC
Weakness type
Related vulnerabilities
- CVE-2025-27920 — Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By us
- CVE-2024-6746 — NaiboWang EasySpider HTTP GET Request server.js path traversal
- CVE-2023-52076 — Remote Code Execution Vulnerability in Atril's EPUB ebook parsing
- CVE-2026-39813 — A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.
- CVE-2025-53513 — Zip slip vulnerability in Juju
- CVE-2024-23657 — Path Traversal: '../filedir' in Nuxt Devtools
- CVE-2025-60344 — A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attacker
- CVE-2023-1800 — sjqzhang go-fastdfs File Upload uploa upload path traversal