---
id: CVE-2020-37278
title: >-
  Weaver e-Bridge contains an unauthenticated arbitrary file read vulnerability
  that allows remote attackers to access arbitrary files on the host system by
  supplying a file: URL to the downloadUrl parameter of the saveYZJFile endpoint
summary: >-
  Weaver e-Bridge contains an unauthenticated arbitrary file read vulnerability
  that allows remote attackers to access arbitrary files on the host system by
  supplying a file: URL to the downloadUrl parameter of the saveYZJFile
  endpoint. At…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-918
vendor: Weaver
product: e-Bridge
affected:
  - e-Bridge
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T21:16:53.620'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-37278'
references:
  - url: >-
      https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/weaver/weaver-ebridge-lfi.yaml
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/weaver-e-bridge-unauthenticated-arbitrary-file-read-via-saveyzjfile
    label: disclosure@vulncheck.com
  - url: 'https://www.weaver.com.cn/cs/ebridge_full_log_en.html'
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-10-02T20:14:06.362998Z'
ingestedAt: '2026-10-02T22:33:09.840Z'
---

## Overview

Weaver e-Bridge contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to access arbitrary files on the host system by supplying a file: URL to the downloadUrl parameter of the saveYZJFile endpoint. Attackers can exploit this flaw to read sensitive files such as /etc/passwd or configuration and credential files, and the same endpoint's support for http(s) URLs also enables server-side request forgery against internal network resources. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-17.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
