MERCUSYS Mercury X18G 1.0.5 devices are vulnerable to local file inclusion via ../ in conjunction with a loginLess or login.htm URI (for authentication bypass) to the web server, as demonstrated by the /loginLess/../../etc/passwd URI.
View the template here CVE-2021-23241.yaml
References:
https://www.mercurycom.com.cn/product-521-1.html