CVE-2024-25830: F-Logic DATACUBE3 Firmware
Critical severity, CVSS 9.8. EPSS: 24% chance of exploitation in the next 30 days.
F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this, by sending a URI that contains the path of the configuration file. A successful exploit could allow the attacker to extract the root and admin password.
Affected products
- F-Logic DATACUBE3 Firmware: version 1.0 only
Published 2024-02-29. Last modified 2026-06-17.