S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-25216 Scanner

CVE-2022-25216 scanner - Path Traversal vulnerability in DVDFab 12 Player (PlayerFab)

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-25216
7.5
CVSS

An absolute path traversal vulnerability allows a remote attacker to download any file on the Windows file system for which the user account running DVDFab 12 Player (recently renamed PlayerFab) has read-access, by means of an HTTP GET request to http://<IP_ADDRESS>:32080/download/<URL_ENCODED_PATH>.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
DVDFab 12 Player / PlayerFabby n/a
6.2.1.0 - 7.0.0.5
Updated Aug 22, 2026View on NVD →
Detail

PlayerFab by DVDFab is a popular media player frequently used by Windows users. This product is designed to provide users with an entertaining, visually-stunning, and uninterrupted experience while watching movies and other types of digital media. Serendipitously, this product has been deemed vulnerable to a newly discovered security breach - CVE-2022-25216.

The CVE-2022-25216 vulnerability detected in PlayerFab is a security loophole that could be exploited remotely, enabling attackers to download any file on the Windows file system accessible by the user account running the application, provided it has read-access. This is done through an HTTP GET method to the specified URL encoded path. Once targeted, this security vulnerability could give attackers a broad range of unauthorized access to digital assets, which would significantly impact the user's confidentiality, integrity, and availability protections.

When exploited, the CVE-2022-25216 vulnerability could lead to significant risks and challenges for the user, including the loss of sensitive intellectual property, financial data and personal information, and reputational harm. Attackers could also use this security threat to launch secondary attacks, including ransomware, denial of service, or trojans into the system, thereby rendering user data unusable or impacting its resiliency.

Thanks to s4e.io, users can safeguard their digital assets from similar security breaches. With the unique pro features of this platform, users can stay up-to-date on the latest security vulnerabilities in their digital domains, providing exceptional security and peace of mind.

 

REFERENCES

Solution Advice

However, several precautions can be taken to address this critical security issue and reduce vulnerabilities in PlayerFab. These precautions include the following:

  • Update your PlayerFab to the latest version 
  • Use a robust antivirus or anti-malware suite 
  • Get acquainted with the PlayerFab's file permissions system
  • Run periodic scans and security tests regularly 
  • Be mindful of untrusted emails or websites 

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-25216 scanner - Path Traversal vulnerability in DVDFab 12 Player (PlayerFab) | S4E