CVE-2016-10106

CWE-22Path Traversal3 documents3 sources
Severity
6.5MEDIUM
EPSS
0.8%
top 25.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 3
Latest updateMay 17

Description

Directory traversal vulnerability in scgi-bin/platform.cgi on NETGEAR FVS336Gv3, FVS318N, FVS318Gv2, and SRX5308 devices with firmware before 4.3.3-8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the thispage parameter, as demonstrated by reading the /etc/shadow file.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jw53-hv9m-v5j8: Directory traversal vulnerability in scgi-bin/platform2022-05-17
CVEList
CVE-2016-10106: Directory traversal vulnerability in scgi-bin/platform2017-01-03
CVE-2016-10106 (MEDIUM CVSS 6.5) | Directory traversal vulnerability i | cvebase.io