CVE-2017-7237

CRITICAL

Spiceworks Inventory <7.5 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-7237. PoCs published by hyp3rlinx.

AI-analyzed exploit summary This advisory describes an improper access control vulnerability in Spiceworks TFTP Server (CVE-2017-7237), allowing unauthenticated remote attackers to overwrite or upload arbitrary files to the 'data\configurations' directory via UDP port 69. The proof-of-concept demonstrates file overwrite and arbitrary file upload using TFTP commands.

Description

The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spiceworks data\configurations directory by leveraging the unauthenticated nature of the TFTP service for all clients who can reach UDP port 69, as demonstrated by a WRQ (aka Write request) operation for a configuration file or an executable file.

Exploits (1)

exploitdb WRITEUP
by hyp3rlinx · textremotewindows
https://www.exploit-db.com/exploits/41825

This advisory describes an improper access control vulnerability in Spiceworks TFTP Server (CVE-2017-7237), allowing unauthenticated remote attackers to overwrite or upload arbitrary files to the 'data\configurations' directory via UDP port 69. The proof-of-concept demonstrates file overwrite and arbitrary file upload using TFTP commands.

Classification
Writeup 100%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: Spiceworks 7.5
No auth needed
Prerequisites: Network access to UDP port 69 on the target · Knowledge or guess of target filename
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/41825/

Scores

CVSS v3 9.8
EPSS 0.0672
EPSS Percentile 93.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
spiceworks/spiceworks 7.5
Published Apr 06, 2017
Tracked Since Feb 18, 2026