Record summary

CVE-2014-2962 has a selected CVSS score of 7.8; EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Absolute path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware before 1.00.08 allows remote attackers to read arbitrary files via a full pathname in the getpage parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBBelkin N150 Router 1.00.08/1.00.09 - Directory TraversalExploitDB exploitby Rahul Pratap SinghNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHBelkin N150 Router 1.00.08/1.00.09 - Path TraversalCVSS 7.8

A path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware before 1.00.08 allows remote attackers to read arbitrary files via a full pathname in the getpage parameter.

Impact

An attacker can exploit this vulnerability to view sensitive files, potentially leading to unauthorized access, data leakage, or further compromise of the system.

Remediation

Ensure that appropriate firewall rules are in place to restrict access to port 80/tcp from external untrusted sources.

WeaknessesCWE-22
Authorsdaffainfo
Template tagscve2014cvelfirouterfirmwaretraversalbelkinvuln
CVSS vector: CVSS:2.0/AV:N/AC:L/Au:N/C:C/I:N/A:N
CPE: cpe:2.3:o:belkin:n150_f9k1009_firmware:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

4