/Vulnerability Library

SolarView Compact < 6.00 - Directory Traversal

CVE-2023-40924
Verified

Description

SolarView Compact before version 6.00 is vulnerable to directory traversal via the file parameter in downloader.php. An unauthenticated attacker can read arbitrary files from the system by using path traversal sequences with a null byte bypass to access sensitive files such as /etc/passwd.

Severity

High

CVSS Score

7.5

Exploit Probability

3%

Affected Product

solarview_compact_firmware

Published Date

April 6, 2026

Template Author

dhiyaneshdk

CVE-2023-40924.yaml
7.5Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2023-40924
CWE ID:
cwe-22

References

https://github.com/Yobing1/CVE-2023-40924/blob/main/README.mdhttps://nvd.nist.gov/vuln/detail/CVE-2023-40924

Remediation Steps

Upgrade SolarView Compact to version 6.00 or later.