CVE Database
/

CVE-2021-4463

Back to search

CVE-2021-4463

Published: Nov 12, 2025

Modified: May 14, 2026

PUBLISHED

Description

Longjing Technology BEMS API versions up to and including 1.21 contains an unauthenticated arbitrary file download vulnerability in the 'downloads' endpoint. The 'fileName' parameter is not properly sanitized, allowing attackers to craft traversal sequences and access sensitive files outside the intended directory.

VendorProductVersions

Shenzhen Longjing Technology Co. Ltd.

BEMS API

affected
0 - <= 1.21

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now