| Description: | | The fnOS has recently been exposed to a path traversal vulnerability. This vulnerability originated from the app-center-static interface (used to provide application static resources). During the backend processing of parameters, only simple string concatenation was performed without verifying the path jump symbol. Attackers can construct special requests to traverse the entire directory and read the core configuration and user data. Under certain conditions, it can also evolve into remote command execution (RCE), enabling complete control of the device. |