9.8
CVSSv3

CVE-2023-27105

Published: 25/04/2023 Updated: 04/05/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A vulnerability in the Wi-Fi file transfer module of Shanling M5S Portable Music Player with Shanling MTouch OS v4.3 and Shanling M2X Portable Music Player with Shanling MTouch OS v3.3 allows malicious users to arbitrarily read, delete, or modify any critical system files via directory traversal.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

shanling eddict player 2.1.3

shanling mtouch_os 3.3

Github Repositories

[ID] CVE-2023-27105 [Affected Products and Versions] Shanling Eddict Player v213 (Android Application) Shanling Mtouch OS v33 (firmware for Shanling M2x Music Player) [Vulnerability Type] Directory Traversal [Description] A vulnerability in the Wi-Fi file transfer module of "Mtouch OS" allows attackers to arbitrarily read, delete or modify critical system files of