HarborGuard / CVE
Back to search
HIGHCVE-2026-1523Published Modified CNA INCIBE

CVE-2026-1523: Path Traversal in Digitek from Grupo Azkoyen

Path Traversal vulnerability in Digitek ADT1100 and Digitek DT950 from PRIMION DIGITEK, S.L.U (Azkoyen Group). This vulnerability allows an attacker to access arbitrary files in the server's file system, thet is, 'http://<host>/..%2F..% 2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd'. By manipulating the input to include URL encoded directory traversal sequences (e.g., %2F representing /), an attacker can bypass the input validation mechanisms ans retrieve sensitive files outside the intended directory, which could lead to information disclosure or further system compromise.

Metrics

CVSS v4.0
8.7
Severity
HIGH
Fixed in
Affected Products
2
Affected packages
  • PRIMION DIGITEK / Digitek ADT1100
    all versions
  • PRIMION DIGITEK / Digitek DT950
    all versions
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
References