CVE-2017-17739
CRITICALBrightSign 4k242 Firmware < 6.2.63 - Path Traversal and Arbitrary File Write via /storage.html rp Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-17739. PoCs published by Information Paradox.
AI-analyzed exploit summary The writeup describes multiple vulnerabilities in BrightSign Digital Signage (Firmware 6.2.63 and below), including XSS, directory traversal, and unauthenticated file upload/modification. These can be combined to compromise the device and end users.
Description
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has directory traversal via the /storage.html rp parameter, allowing an attacker to read or write to files.
Exploits (1)
The writeup describes multiple vulnerabilities in BrightSign Digital Signage (Firmware 6.2.63 and below), including XSS, directory traversal, and unauthenticated file upload/modification. These can be combined to compromise the device and end users.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H