github.com
https://github.com/coincoin7/Wireless-Router-Vulnerability/blob/master/TplinkLocalePathDisclosure.txt CVE-2017-16959
MEDIUM
TP-Link tl-wvr300_firmware Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2017-16959 has a selected CVSS score of 6.5 (medium).
Description
The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of arbitrary files by making an operation=write;locale=%0d request, and then making an operation=read request with a crafted Accept-Language HTTP header, related to the set_sysinfo and get_sysinfo functions in /usr/lib/lua/luci/controller/locale.lua in uhttpd.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 7, 2013 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
tl-wvr300_firmwareBrowse TP-Link / tl-wvr300_firmware | VulnCheck | Version data not supplied | |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-16959