vendor:
Routers
by:
An independent security researcher
7,5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Routers
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2017-15647
CPE: h:fiberhome:router
Metasploit:
N/A
Other Scripts:
N/A
Tags: lfi,router,edb,cve,cve2017
CVSS Metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Nuclei Metadata: {'max-request': 1, 'vendor': 'fiberhome', 'product': 'routerfiberhome_firmware'}
Platforms Tested: Unknown
2017
Directory Traversal Vulnerability in FiberHome Routers
FiberHome routers are susceptible to local file inclusion in /cgi-bin/webproc via the getpage parameter in conjunction with a crafted var:page value.
Mitigation:
At this time there is no solution or workaround for the vulnerability.