CVE-2025-27716 Details
Description
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file/folder listing process of the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, the product's files may be obtained and/or altered by a crafted HTTP request to specific functions of the product from a device connected to the LAN side.
A path traversal vulnerability has been identified in the USB storage file-sharing function of the KDDI HGW-BL1500HM home gateway, specifically in versions through 002.002.003. This vulnerability arises from improper limitations on pathnames, allowing files to be accessed or modified by sending a crafted HTTP request to certain functions of the product from a device connected to the LAN.
Users are advised to update the firmware to the latest version. The device automatically communicates with KDDI's central system to download and install new firmware, maintaining an optimal state. No user action is required, but the device should be connected to the internet and powered on.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 28, 2025CISA-ADP
Assessed Mar 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/jp/JVN04278547/ | [email protected] | AdvisoryBundleRemedy |
| https://kddi-tech.com/contents/appendix_L2_06.html#64433e4a-8946-9c06-bddf-91cbfe56c8e5 | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| KDDI HGW-BL1500HM | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 28, 2025 | New CVE Received | [email protected] |
Volerion