vendor:
Router
by:
Todor Donev
8,8
CVSS
HIGH
Remote File Inclusion
98
CWE
Product Name: Router
Affected Version From: 2.3.9
Affected Version To: 2.3.9
Patch Exists: YES
Related CWE: N/A
CPE: h:seowonintech:router
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2013
Seowonintech routers <= fw: 2.3.9 remote root file dumper
This exploit allows an attacker to remotely dump files from a Seowonintech router running firmware version 2.3.9 or lower. The exploit is written in Perl and uses the LWP::Simple module to connect to the router and retrieve the contents of the requested file. The exploit is triggered by passing the full path of the file to be dumped as an argument to the script.
Mitigation:
Upgrade to the latest firmware version and ensure that all security patches are applied.