A directory traversal vulnerability exists in TVT NVMS-1000 devices, where an attacker can exploit the GET method with '/../' sequences to access files and directories outside the intended web root. This allows unauthorized access to arbitrary files on the device.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a simple Python proof-of-concept exploit for CVE-2019-20085 affecting TVT NVMS-1000. Structure: (1) `CVE-2019-20085.py` is the only code file; it takes three CLI args: base URL, target filename/path, and a local output filename. It constructs a traversal string (`../../...`) and performs an unauthenticated `requests.get()` to `<base_url><traversal><filename>`, enabling arbitrary file read (LFI/directory traversal) over the network. If HTTP 200 is returned, it writes the response body to the specified local output file (using `os.system('touch ...')` then Python file write). (2) `README.md` documents the vulnerability, affected product (NVMS-1000 on Windows), and provides an example request using encoded backslashes (`..%5C`) and a sample target file (`windows\win.ini`). No post-exploitation beyond file retrieval is implemented; no scanning, brute force, or shell payloads are present.
This repository contains a single Metasploit auxiliary module targeting a directory traversal vulnerability (CVE-2019-20085) in TVT NVMS-1000 version 3.4.1. The module exploits an unauthenticated HTTP endpoint (default port 80) to read arbitrary files from the target system by sending a crafted GET request with a directory traversal path. The user can specify the file path and traversal depth; by default, it attempts to read '/windows/win.ini'. The exploit saves the retrieved file locally. The code is written in Ruby and is structured as a typical Metasploit auxiliary scanner module, with all logic contained in the 'run_host' method. No detection or fake code is present; this is a functional exploit for file disclosure via network attack vector.
This repository contains a Bash proof-of-concept exploit for CVE-2019-20085, a directory traversal vulnerability in NVMS-1000. The main exploit script, 'cve-2019-20085-poc.sh', takes a target URL and a file path as arguments. It constructs an HTTP request with a directory traversal payload (a long sequence of '../') appended to the URL, followed by the desired file path. The script first checks if the target is vulnerable by sending a request and checking for a 200 HTTP response code. If successful, it retrieves and displays the contents of the specified file from the target server. The exploit is network-based and requires the attacker to know the target's URL and the file they wish to access. The repository is structured simply, with a README providing usage instructions and a single Bash script implementing the exploit logic.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.