vendor:
GWG
by:
An independent security researcher
7,5
CVSS
HIGH
Path Traversal
22
CWE
Product Name: GWG
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: CVE-2017-11456
CPE: h:geneko:gwg
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2017
Unauthenticated Path Traversal vulnerability in Geneko GWR routers series
User controlled input is not sufficiently sanitized, and then passed to a function responsible for accessing the filesystem. Successful exploitation of this vulnerability enables a remote unauthenticated user to read the content of any file existing on the host, this includes files located outside of the web root folder. By sending a GET request, an attacker can get direct access to the configuration file, which allows them to log in to the login panel.
Mitigation:
No patch or workaround is available from the vendor.