CVE-2016-10106
published 2017-01-03CVE-2016-10106: Directory traversal vulnerability in scgi-bin/platform.cgi on NETGEAR FVS336Gv3, FVS318N, FVS318Gv2, and SRX5308 devices with firmware before 4.3.3-8 allows…
PriorityP338medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
2.43%
82.3th percentile
Directory traversal vulnerability in scgi-bin/platform.cgi on NETGEAR FVS336Gv3, FVS318N, FVS318Gv2, and SRX5308 devices with firmware before 4.3.3-8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the thispage parameter, as demonstrated by reading the /etc/shadow file.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | fvs318gv2_firmware | <= 4.3-3.6 | — |
| netgear | fvs318n_firmware | <= 4.3-3.6 | — |
| netgear | fvs336gv3_firmware | <= 4.3-3.6 | — |
| netgear | srx5308_firmware | <= 4.3-3.6 | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://kb.netgear.com/30739/Path-Traversal-Attack-Security-Vulnerabilityhttp://www.securityfocus.com/bid/95204http://www.securitytracker.com/id/1037548https://twitter.com/mantislesin/status/816618162770821120http://kb.netgear.com/30739/Path-Traversal-Attack-Security-Vulnerabilityhttp://www.securityfocus.com/bid/95204http://www.securitytracker.com/id/1037548https://twitter.com/mantislesin/status/816618162770821120
2017-01-03
Published