Cellopoint CelloOS - Unauthenticated Arbitrary File Disclosure
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 1.6%
exploitation probability
1.6%top 26% of all CVEs
observed exploitation
nono source reports it
Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly, which allows unauthorized user to launch Path Traversal attack and access arbitrate file on the system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
Cellopoint · CelloOS