vendor:
SPH200D
by:
s3cur1ty
8,8
CVSS
HIGH
Directory Traversal and Password Change
22
CWE
Product Name: SPH200D
Affected Version From: 1.0.4.80
Affected Version To: 1.0.4.80
Patch Exists: YES
Related CWE: N/A
CPE: h:netgear:sph200d
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2017
Netgear SPH200D Directory Traversal and Password Change Vulnerability
Netgear SPH200D is vulnerable to directory traversal and password change. An attacker can access local files of the device and change the current password without knowing it.
Mitigation:
Upgrade to the latest version of the firmware.