Vulnerability Description
In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../ directory traversal in the username field. Reading ServerParameters.xml may reveal administrator credentials in cleartext or with MD5 hashing.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Infodraw | Pmrs-102 Firmware | 7.1.0.0 |
| Infodraw | Pmrs-102 | - |
Related Weaknesses (CWE)
References
- https://cfp.eh22.easterhegg.eu/eh22/talk/9UDXSE/Not Applicable
- https://mint-secure.de/path-traversal-vulnerability-in-surveillance-software/ExploitThird Party Advisory
FAQ
What is CVE-2025-43928?
CVE-2025-43928 is a vulnerability with a CVSS score of 5.8 (MEDIUM). In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../ directory traversal in the username field. Reading ServerParameters.xml may rev...
How severe is CVE-2025-43928?
CVE-2025-43928 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-43928?
Check the references section above for vendor advisories and patch information. Affected products include: Infodraw Pmrs-102 Firmware, Infodraw Pmrs-102.