Vulnerability record · CVE-2012-4031 · published 17 July 2012
CVE-2012-4031: Wangkongbao CNS-1000/1100 directory traversal in acloglogin.php
Wangkongbao · Cns 1000
src/acloglogin.php in Wangkongbao CNS-1000 and CNS-1100 fails to sanitize the lang and langid cookies, allowing directory traversal. An attacker can read arbitrary files on the device through crafted cookie values. The flaw exposes configuration and credential material on an internet-reachable appliance.
Description
Multiple directory traversal vulnerabilities in src/acloglogin.php in Wangkongbao CNS-1000 and 1100 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) lang or (2) langid cookie to port 85.
AV:N/AC:L/Au:N/C:P/I:N/A:N
Automated analysis
high priorityUnauthenticated remote file read with public exploit code and very high EPSS, though not in KEV and rated only MEDIUM by CVSS 2.0.
What it is
src/acloglogin.php in Wangkongbao CNS-1000 and CNS-1100 fails to sanitize the lang and langid cookies, allowing directory traversal. An attacker can read arbitrary files on the device through crafted cookie values. The flaw exposes configuration and credential material on an internet-reachable appliance.
Impact
An unauthenticated attacker gains read access to arbitrary files on the device, which can leak credentials, configuration and other sensitive data. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reachable over the network against port 85 of the appliance; no authentication or user interaction is required per the CVSS vector AV:N/AC:L/Au:N. The attack is delivered through the lang or langid cookie.
Exploitation
Public exploit code exists (Exploit-DB and SecurityFocus references tagged Exploit), and EPSS is high at roughly 0.52 (99th percentile), but the CVE is not listed in CISA KEV.
What to do
- Apply the vendor fix or firmware update for CNS-1000/CNS-1100; if none is available, isolate the device.
- Restrict access to port 85 to trusted management networks and block it from the internet.
- Filter or reject cookie values containing path traversal sequences such as '..' at a reverse proxy or WAF.
- Replace end-of-life appliances that no longer receive security updates.
Detection
- Inspect web logs for requests to acloglogin.php with lang or langid cookies containing '..' or encoded traversal sequences.
- Alert on HTTP requests to port 85 from untrusted sources or unexpected geographies.
- Monitor for file-read patterns or unusual outbound traffic from the appliance that could indicate data exfiltration.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-4031 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-4031), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.