CVE-2017-12943
CRITICALD-Link DIR-600 B1 v2.x - Unauthenticated Path Traversal via __show_info.php REQUIRE_FILE Parameter
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2017-12943. PoCs published by Jithin D Kurup, d4rk30, aymankhalfatni.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass via absolute path traversal in D-Link DIR-600 routers (firmware 2.01). By appending a specific payload to the URL, an attacker can read the admin password from the httpasswd file.
Description
D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to read passwords via a model/__show_info.php?REQUIRE_FILE= absolute path traversal attack, as demonstrated by discovering the admin password.
Exploits (3)
This exploit demonstrates an authentication bypass via absolute path traversal in D-Link DIR-600 routers (firmware 2.01). By appending a specific payload to the URL, an attacker can read the admin password from the httpasswd file.
This repository contains a README file describing an authentication bypass vulnerability (CVE-2017-12943) in D-Link DIR-600 modems. The writeup is in Arabic and explains how to exploit the flaw to gain unauthorized access without a password.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H