CVE-2019-17187: Fiberhome HG2201T Firmware

High severity, CVSS 7.5. EPSS: 10.8% chance of exploitation in the next 30 days.

/var/WEB-GUI/cgi-bin/downloadfile.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication Directory Traversal for reading arbitrary files.

Affected products

  • Fiberhome HG2201T Firmware: version 1.00.m5007_js_201804 only

Published 2019-10-08. Last modified 2026-06-17.