CVE-2019-7387: Systrome Isg-600c Firmware
Medium severity, CVSS 6.5. EPSS: 1.4% chance of exploitation in the next 30 days.
A local file inclusion vulnerability exists in the web interface of Systrome Cumilon ISG-600C, ISG-600H, and ISG-800W 1.1-R2.1_TRUNK-20180914.bin devices. When the export function is called from system/maintenance/export.php, it accepts the path provided by the user, leading to path traversal via the name parameter.
Affected products
- Systrome Isg-600c Firmware: version 1.1-r2.1_trunk-20180914 only
- Systrome Isg-600h Firmware: version 1.1-r2.1_trunk-20180914 only
- Systrome Isg-800w Firmware: version 1.1-r2.1_trunk-20180914 only
Published 2019-02-04. Last modified 2026-06-17.