VYPR
Unrated severityNVD Advisory· Published Jan 31, 2023· Updated Mar 27, 2025

ChangingTec MegaServiSignAdapter - Path Traversal

CVE-2022-39059

Description

ChangingTech MegaServiSignAdapter component has a path traversal vulnerability within its file reading function. An unauthenticated remote attacker can exploit this vulnerability to access arbitrary system files.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An unauthenticated path traversal in MegaServiSignAdapter allows remote attackers to read arbitrary system files.

Vulnerability

The MegaServiSignAdapter component from ChangingTech (MegaServiSignAdapter Windows version v1.0.17.0823) contains a path traversal vulnerability in its file reading function. The vulnerability arises because user-supplied path parameters are not properly sanitized, allowing directory traversal sequences to escape the intended directory. The affected versions include v1.0.17.0823 and likely earlier releases [1].

Exploitation

An unauthenticated remote attacker can exploit this vulnerability by sending a crafted HTTP request to the affected file reading function with path traversal sequences (e.g., ../). No prior authentication or user interaction is required. The attacker must be able to reach the service over the network [1].

Impact

Successful exploitation allows the attacker to bypass authentication mechanisms and read arbitrary files on the system. This leads to disclosure of sensitive information such as configuration files, credentials, or other confidential data, resulting in a high confidentiality impact with no impact on integrity or availability [1].

Mitigation

The vendor has released version v1.0.22.1004 which fixes the vulnerability. Users should update to this version immediately. No known workarounds are available for unpatched versions. The vulnerability is not currently listed on the CISA KEV [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.