CVE-2013-4861: Micasaverde Veralite Firmware
Medium severity, CVSS 6.5. EPSS: 6.6% chance of exploitation in the next 30 days.
Directory traversal vulnerability in cgi-bin/cmh/get_file.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote authenticated users to read arbirary files via a .. (dot dot) in the filename parameter.
Affected products
- Micasaverde Veralite Firmware: version 1.5.408 only
Published 2020-01-28. Last modified 2026-06-16.