CVE-2017-15647

HIGH NUCLEI

FiberHome Routers - Local File Inclusion

Title source: nuclei
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-15647. PoCs published by SecuriTeam. A Nuclei detection template is also available.

AI-analyzed exploit summary The exploit demonstrates a directory traversal vulnerability in FiberHome routers via the /cgi-bin/webproc endpoint. By manipulating the 'getpage' parameter, an attacker can retrieve arbitrary files from the router's filesystem, such as /etc/shadow.

Description

On FiberHome routers, Directory Traversal exists in /cgi-bin/webproc via the getpage parameter in conjunction with a crafted var:page value.

Exploits (1)

exploitdb WORKING POC
by SecuriTeam · webappslinux
https://www.exploit-db.com/exploits/44054

The exploit demonstrates a directory traversal vulnerability in FiberHome routers via the /cgi-bin/webproc endpoint. By manipulating the 'getpage' parameter, an attacker can retrieve arbitrary files from the router's filesystem, such as /etc/shadow.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: FiberHome routers (version unspecified)
No auth needed
Prerequisites: Network access to the router's web interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

FiberHome Routers - Local File Inclusion
HIGHby daffainfo

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://blogs.securiteam.com/index.php/archives/3472

Scores

CVSS v3 7.5
EPSS 0.2662
EPSS Percentile 97.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (1)
fiberhome/routerfiberhome_firmware
Published Oct 19, 2017
Tracked Since Feb 18, 2026