CVE-2017-11456
HIGHGeneko GWR Router Firmware - Unauthenticated Path Traversal via /../ Substring
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-11456. PoCs published by SecuriTeam.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated path traversal vulnerability in Geneko GWR routers, allowing remote attackers to read arbitrary files, including sensitive configuration files like `/etc/shadow` and `/mnt/flash/params/j_admin_admin.params`. The PoC includes a Python script to fetch the `/etc/shadow` file, confirming the vulnerability.
Description
Geneko GWR routers allow directory traversal sequences starting with a /../ substring, as demonstrated by unauthenticated read access to the configuration file.
Exploits (1)
This exploit demonstrates an unauthenticated path traversal vulnerability in Geneko GWR routers, allowing remote attackers to read arbitrary files, including sensitive configuration files like `/etc/shadow` and `/mnt/flash/params/j_admin_admin.params`. The PoC includes a Python script to fetch the `/etc/shadow` file, confirming the vulnerability.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N