SNT found that MOTU AVB devices contain a directory traversal vulnerability. During testing, SNT was able to append characters to the end of the URL and manipulate the application to display local files.
For example, when using the URL of
The application responds with the listing of the /etc/passwd file.
The vendor has not acknowledged this vulnerability and therefore no patch or fix exists. SNT recommends removing any external network access that this device may have.
Credit: James Carroll and Adam Pawloski, Secure Network Technologies, Inc.