CVE-2018-5997: Ravpower Filehub Firmware

Critical severity, CVSS 9.8. EPSS: 23.5% chance of exploitation in the next 30 days.

An issue was discovered in the HTTP Server in RAVPower Filehub 2.000.056. Due to an unrestricted upload feature and a path traversal vulnerability, it is possible to upload a file on a filesystem with root privileges: this will lead to remote code execution as root.

Affected products

  • Ravpower Filehub Firmware: version 2.000.056 only

Published 2018-01-25. Last modified 2026-06-17.