Security Advisory

CVE-2021-4463

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-11-12 22:07:30
Last updated 2026-05-14 02:06:50
Assigner VulnCheck
CVSS score 8.7
State PUBLISHED

Description

Longjing Technology BEMS API versions up to and including 1.21 contains an unauthenticated arbitrary file download vulnerability in the 'downloads' endpoint. The 'fileName' parameter is not properly sanitized, allowing attackers to craft traversal sequences and access sensitive files outside the intended directory.