CVE-2014-2962
NUCLEIBelkin N150 F9K1009 Firmware < 1.00.08 - Path Traversal via getpage Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-2962. PoCs published by Rahul Pratap Singh. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a path traversal vulnerability in Belkin N150 routers (firmware versions 1.00.07 and earlier). The `getpage` parameter in the `webproc` CGI module allows arbitrary file reads, including sensitive files like `/etc/passwd`.
Description
Absolute path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware before 1.00.08 allows remote attackers to read arbitrary files via a full pathname in the getpage parameter.
Exploits (1)
This exploit demonstrates a path traversal vulnerability in Belkin N150 routers (firmware versions 1.00.07 and earlier). The `getpage` parameter in the `webproc` CGI module allows arbitrary file reads, including sensitive files like `/etc/passwd`.