CVE-2025-27726
Description
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file download process of the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, the product's files may be obtained and/or altered by a crafted HTTP request to specific functions of the product from a device connected to the LAN side.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A path-traversal vulnerability in the USB storage file-sharing function of HGW-BL1500HM allows LAN-side attackers to obtain and alter product files via crafted HTTP requests.
Vulnerability
Overview
The HGW-BL1500HM home gateway (Ver 002.002.003 and earlier) contains a path-traversal vulnerability (CVE-2025-27726) in the file download process of its USB storage file-sharing function. The issue is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory)[1].
Attack
Vector and Prerequisites
An attacker must have network access from the LAN side, be able to send crafted HTTP requests to specific functions of the product, and have low-privilege credentials (CVSS PR:L). The attack complexity is low but requires physical or adjacent network proximity (CVSS AV:P)[1].
Impact
Successful exploitation allows the attacker to read arbitrary files from the device. The official description notes that files may be obtained and/or altered via a crafted HTTP request[1]. The CVSS v3 base score is 2.1 (Low), reflecting a limited confidentiality impact and no impact on integrity or availability for this specific vector[1].
Mitigation and
Remediation
KDDI has published a firmware update (version 002.004.010) that addresses this and other reported vulnerabilities[2]. Users are advised to ensure the gateway is connected to the internet and powered on to receive automatic firmware updates, or to apply the update as described in KDDI's advisory[2].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.