vendor:
RG4332
by:
Saeid Atabaki
8,8
CVSS
HIGH
Arbitrary File Read
22
CWE
Product Name: RG4332
Affected Version From: RG4332_V2.7.0
Affected Version To: RG4332_V2.7.0
Patch Exists: YES
Related CWE: N/A
CPE: h:technicolor:rg4332
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: RG4332
2017
TM RG4332 Wireless Router Traversal Arbitrary File Read
This exploit allows an attacker to read arbitrary files on the TM RG4332 Wireless Router. By sending a specially crafted HTTP request, an attacker can traverse the directory structure of the router and read any file on the system. This vulnerability is due to insufficient input validation of the 'getpage' parameter in the webproc CGI script.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update their router to the latest version.