CVE-2015-7245
published 2017-04-24CVE-2015-7245: Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remote attackers to read sensitive…
PriorityP265high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EXPLOIT
EPSS
45.48%
98.7th percentile
Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remote attackers to read sensitive information via a .. (dot dot) in the errorpage parameter.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-link | dvg-n5402sp_firmware | — | — |
| d-link | dvg-n5402sp_firmware | — | — |
| d-link | dvg-n5402sp_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
commandgetpage=html%2Findex.html&*errorpage*=../../../../../../../../../../../etc/passwd&var%3Amenu=setup&var%3Apage=connected&var%&objaction=auth&%3Ausername=blah&%3Apassword=blah&%3Aaction=login&%3Asessionid=abcdefgh↗
commandgetpage=html%2Findex.html&*errorpage*=../../../../../../../../../../../etc/shadow&var%3Amenu=setup&var%3Apage=connected&var%
&objaction=auth&%3Ausername=blah&%3Apassword=blah&%3Aaction=login&%3Asessionid=abcdefgh↗
- →Exploit requires no authentication; detect unauthenticated POST requests to /cgi-bin/webproc containing directory traversal sequences (../) in the 'errorpage' parameter. ↗
- →Alert on POST body containing the 'errorpage' parameter with path traversal sequences targeting sensitive files such as /etc/passwd or /etc/shadow. ↗
- →Successful exploitation returns /etc/shadow content in the HTTP response body; match on patterns like 'root::' followed by numeric fields in responses from the device. ↗
- →Device management interface is exposed on port 8080; monitor for traversal attempts on this non-standard port targeting /cgi-bin/webproc. ↗
- →Default hardcoded credentials root:root and tw:tw may be used for Telnet access post-exploitation; monitor Telnet login attempts with these credentials. ↗
- ·Vulnerability affects only specific firmware versions; detection should be scoped to devices running W1000CN-00, W1000CN-03, or W2000EN-00. ↗
- ·The 'tw' login account is not active by default, reducing the Telnet attack surface for that credential, though root:root remains a risk when Telnet is enabled. ↗
- ·The restricted 'support' user can also access the configuration backup file, meaning privilege escalation is possible from a low-privilege account without exploiting the path traversal. ↗
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
D-Link DVGN5402SP - Multiple Vulnerabilities
exploitdb·2016-02-04·CVSS 7.5
CVE-2015-7247 [HIGH] D-Link DVGN5402SP - Multiple Vulnerabilities
D-Link DVGN5402SP - Multiple Vulnerabilities
---
# Exploit Title: [DLink DVGN5402SP Multiple Vulnerabilities]
# Discovered by: Karn Ganeshen
# Vendor Homepage: [www.dlink.com/]
# Versions Reported: [Multiple - See below]
# CVE-IDs: [CVE-2015-7245 + CVE-2015-7246 + CVE-2015-7247]
*DLink DVGN5402SP File Path Traversal, Weak Credentials Management, and
Sensitive Info Leakage Vulnerabilities*
*Vulnerable Models, Firmware, Hardware versions*
DVGN5402SP Web Management
Model Name : GPN2.4P21CCN
Firmware Version : W1000CN00
Firmware Version :W1000CN03
Firmware Version :W2000EN00
Hardware Platform :ZS
Hardware Version :Gpn2.4P21C_WIFIV0.05
Device can be managed through three users:
1. super full privileges
2. admin full privileges
3. support restricted user
*1. Path traversal
Nuclei
D-Link DVG-N5402SP - Local File Inclusion
nuclei·CVSS 7.5
CVE-2015-7245 [HIGH] D-Link DVG-N5402SP - Local File Inclusion
D-Link DVG-N5402SP - Local File Inclusion
D-Link DVG-N5402SP is susceptible to local file inclusion in products with firmware W1000CN-00, W1000CN-03, or W2000EN-00. A remote attacker can read sensitive information via a .. (dot dot) in the errorpage parameter.
Template:
id: CVE-2015-7245
info:
name: D-Link DVG-N5402SP - Local File Inclusion
author: 0x_Akoko
severity: high
description: |
D-Link DVG-N5402SP is susceptible to local file inclusion in products with firmware W1000CN-00, W1000CN-03, or W2000EN-00. A remote attacker can read sensitive information via a .. (dot dot) in the errorpage parameter.
impact: |
An attacker can read sensitive files on the system, potentially leading to unauthorized access or disclosure of sensitive information.
remediation: |
Update the router firmware
No writeups or analysis indexed.
http://packetstormsecurity.com/files/135590/D-Link-DVG-N5402SP-Path-Traversal-Information-Disclosure.htmlhttp://seclists.org/fulldisclosure/2016/Feb/24https://www.exploit-db.com/exploits/39409/http://packetstormsecurity.com/files/135590/D-Link-DVG-N5402SP-Path-Traversal-Information-Disclosure.htmlhttp://seclists.org/fulldisclosure/2016/Feb/24https://www.exploit-db.com/exploits/39409/
2017-04-24
Published