CVE-2018-5997: Ravpower Filehub Firmware
Critical severity, CVSS 9.8. EPSS: 23.5% chance of exploitation in the next 30 days.
An issue was discovered in the HTTP Server in RAVPower Filehub 2.000.056. Due to an unrestricted upload feature and a path traversal vulnerability, it is possible to upload a file on a filesystem with root privileges: this will lead to remote code execution as root.
Affected products
- Ravpower Filehub Firmware: version 2.000.056 only
Published 2018-01-25. Last modified 2026-06-17.