CVE-2020-37278
Received Received - Intake

Unauthenticated File Read in Weaver e-Bridge

Vulnerability report for CVE-2020-37278, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

Weaver e-Bridge contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to access arbitrary files on the host system by supplying a file: URL to the downloadUrl parameter of the saveYZJFile endpoint. Attackers can exploit this flaw to read sensitive files such as /etc/passwd or configuration and credential files, and the same endpoint's support for http(s) URLs also enables server-side request forgery against internal network resources. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-17.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-03
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
weaver ebridge *
weaver e-bridge to unlimited (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2020-37278 is an unauthenticated arbitrary file read vulnerability in Weaver e-Bridge. It allows remote attackers to read sensitive files on the host system by supplying a file URL to the downloadUrl parameter of the saveYZJFile endpoint. Attackers can access files like /etc/passwd or configuration files. The same endpoint also supports http(s) URLs, enabling server-side request forgery against internal network resources.

Detection Guidance
  • Use the provided Nuclei template to scan for the vulnerability by sending crafted requests to the saveYZJFile endpoint and checking for responses containing sensitive file content or system paths.
  • Manually test by sending HTTP requests with file:///C:/ or /etc/passwd paths to the saveYZJFile endpoint and observe if the server returns file contents or system information.
Impact Analysis

This vulnerability can lead to unauthorized access to sensitive files, including system files and configuration files containing credentials. Attackers could exploit it to steal confidential data, perform lateral movement within internal networks via SSRF, or gain further access to critical systems.

Compliance Impact

This vulnerability can severely impact compliance with GDPR and HIPAA by enabling unauthorized access to sensitive personal or health data. GDPR requires protection of personal data, and HIPAA mandates safeguards for protected health information. Exploitation could result in data breaches, leading to legal penalties and reputational damage.

Mitigation Strategies
  • Upgrade Weaver e-Bridge to the latest patched version as soon as possible to address the arbitrary file read and SSRF vulnerabilities.
  • Restrict network access to the saveYZJFile endpoint to prevent unauthorized access from external sources.
  • Monitor network traffic for unusual requests targeting the saveYZJFile endpoint or attempts to access sensitive files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2020-37278. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart