SolarView Compact < 6.00 - Directory Traversal
CVE-2023-40924
Verified
Description
SolarView Compact before version 6.00 is vulnerable to directory traversal via the file parameter in downloader.php. An unauthenticated attacker can read arbitrary files from the system by using path traversal sequences with a null byte bypass to access sensitive files such as /etc/passwd.
Severity
High
CVSS Score
7.5
Exploit Probability
3%
Affected Product
solarview_compact_firmware
Published Date
April 6, 2026
Template Author
dhiyaneshdk
CVE-2023-40924.yaml
7.5Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2023-40924
CWE ID:
cwe-22
Remediation Steps
Upgrade SolarView Compact to version 6.00 or later.