CVE-2013-4861: Micasaverde Veralite Firmware

Medium severity, CVSS 6.5. EPSS: 6.6% chance of exploitation in the next 30 days.

Directory traversal vulnerability in cgi-bin/cmh/get_file.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote authenticated users to read arbirary files via a .. (dot dot) in the filename parameter.

Affected products

Published 2020-01-28. Last modified 2026-06-16.