CVE-2019-6268
CVE-2019-6268 is a high-severity vulnerability with a CVSS 3.x base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-31.
Key facts
- Severity: High (CVSS 3.x base score 7.5)
- EPSS exploit prediction: 1% (56th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2019-15834
- Weakness: CWE-31
- Published:
- Last modified:
Description
RAD SecFlow-2 devices with Hardware 0202, Firmware 4.1.01.63, and U-Boot 2010.12 allow URIs beginning with /.. for Directory Traversal, as demonstrated by reading /etc/shadow.
Frequently asked questions
- What is CVE-2019-6268?
- RAD SecFlow-2 devices with Hardware 0202, Firmware 4.1.01.63, and U-Boot 2010.12 allow URIs beginning with /.. for Directory Traversal, as demonstrated by reading /etc/shadow.
- How severe is CVE-2019-6268?
- CVE-2019-6268 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2019-6268 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (56th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2019-6268?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- Does CVE-2019-6268 have an EU (EUVD) identifier?
- Yes. CVE-2019-6268 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2019-15834.
- When was CVE-2019-6268 published?
- CVE-2019-6268 was published on 2024-03-08 and last updated on 2026-06-17.
References
- https://packetstormsecurity.com/files/177440/RAD-SecFlow-2-Path-Traversal.html
- https://www.owasp.org/index.php/Path_Traversal
Other CWE-31 vulnerabilities
- CVE-2024-2044 — Critical (CVSS 9.9): pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session…
- CVE-2024-41376 — High (CVSS 8.8): dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.
- CVE-2024-24998 — High (CVSS 8.8): A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker…
- CVE-2026-104810 — High (CVSS 8.4): This vulnerability allows remote attackers to delete sensitive files on vulnerable installations of Mitel MiVoice…
- CVE-2026-104706 — High (CVSS 8.4): DigitalCanion has discovered a path traversal vulnerability that allows to view or download sensitive system files over…
- CVE-2024-36857 — High (CVSS 7.5): Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.