← Vulnerability feed

Vulnerability record · CVE-2019-20085 · published 30 December 2019

CVE-2019-20085: TVT NVMS-1000 path traversal via GET /..

Tvt · Nvms 1000 Firmware

TVT NVMS-1000 firmware is vulnerable to a directory traversal flaw reachable through a crafted GET /.. request. An unauthenticated remote attacker can read files outside the intended web root, exposing configuration and credential material on an internet-facing NVR/DVR management interface. The record does not list specific affected firmware versions.

7.5 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 96% · top 0.1% CWE-22 · Path traversal
7.5CVSS 3.1 base score, v2 5.0
96%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

TVT NVMS-1000 devices allow GET /.. Directory Traversal

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with public exploit code and an EPSS probability above 0.96, and it exposes files on an unauthenticated network-reachable interface.

What it is

TVT NVMS-1000 firmware is vulnerable to a directory traversal flaw reachable through a crafted GET /.. request. An unauthenticated remote attacker can read files outside the intended web root, exposing configuration and credential material on an internet-facing NVR/DVR management interface. The record does not list specific affected firmware versions.

Impact

An attacker gains read access to arbitrary files on the device filesystem, which can leak stored credentials, configuration and other sensitive data. There is no integrity or availability impact per the CVSS vector.

Attack surface

Reachable over the network through HTTP GET requests to the NVMS-1000 web interface; the CVSS vector shows no privileges and no user interaction required. Any host that can reach the management port can attempt it.

Exploitation

Listed in CISA KEV since 2021-11-03 with a required action deadline of 2022-05-03, and public exploit code exists in Exploit-DB and Packet Storm. EPSS 30-day probability is 0.96071 (99.874th percentile), indicating very high likelihood of exploitation activity.

What to do

  • Apply the vendor update per CISA KEV required action; if no fix is available, isolate or retire the device.
  • Remove NVMS-1000 management interfaces from direct internet exposure; place them behind a VPN or firewall allowlist.
  • Restrict inbound access to the device's HTTP port to trusted management networks only.
  • Rotate any credentials or secrets that may have been stored on or exposed by the device.
  • Monitor vendor advisories for NVMS-1000 and replace end-of-life units that no longer receive firmware updates.

Detection

  • Search web/proxy logs for GET requests containing '/..' or encoded traversal sequences (e.g. %2e%2e) targeting NVMS-1000 hosts.
  • Alert on HTTP requests to NVMS-1000 management endpoints originating from unexpected external or non-management IP ranges.
  • Review device and network logs for anomalous file-read patterns or repeated traversal attempts against the NVR/DVR interface.
  • Inventory internet-exposed NVMS-1000 devices and confirm none are reachable from untrusted networks.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-20085 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "TVT NVMS-1000 Directory Traversal Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-20085 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed5.3CVE-2026-66384JFrog Artifactory path traversal in Docker cache pathAn authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions in JFrog Artifactory. The fla…KEVEPSS 0.66%analysed9.8CVE-2026-59310VMware vCenter Syslog server path traversal leads to RCEVMware vCenter's Syslog server is affected by a directory traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to execute arbitrary…KEVEPSS 2.6%analysed10.0CVE-2026-48282Adobe ColdFusion path traversal leads to remote code executionColdFusion versions 2025.9, 2023.20 and earlier contain a path traversal flaw (CWE-22) that allows an unauthenticated remote attacker to reach files …KEVEPSS 42%analysed10.0CVE-2026-34909UniFi OS path traversal allows unauthenticated file accessUniFi OS devices contain a path traversal flaw (CWE-22) that lets a network-reachable attacker read files on the underlying system. Because the expos…KEVEPSS 1.8%analysed6.5CVE-2026-20262Cisco Catalyst SD-WAN Manager path traversal in file uploadCisco Catalyst SD-WAN Manager (formerly vManage) fails to properly validate user-supplied input during a file upload process, allowing path traversal…KEVEPSS 28%analysed8.4CVE-2024-1708ConnectWise ScreenConnect path traversal enabling remote code executionConnectWise ScreenConnect 23.9.7 and earlier contain a path-traversal flaw (CWE-22) that can let an attacker execute remote code or reach confidentia…KEVEPSS 95%analysed

Source: NIST National Vulnerability Database (record CVE-2019-20085), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.