CVE-2017-9097

CRITICAL

Anti-Web <3.8.7 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-9097. PoCs published by MDudek-ICS.

AI-analyzed exploit summary This repository contains a Python-based PoC for CVE-2017-9097, an LFI vulnerability in Anti-Web server versions 3.0.x to 3.8.x. The exploit sends a crafted POST request to read arbitrary files from the server, including sensitive configuration files like /etc/passwd and user credentials.

Description

In Anti-Web through 3.8.7, as used on NetBiter FGW200 devices through 3.21.2, WS100 devices through 3.30.5, EC150 devices through 1.40.0, WS200 devices through 3.30.4, EC250 devices through 1.40.0, and other products, an LFI vulnerability allows a remote attacker to read or modify files through a path traversal technique, as demonstrated by reading the password file, or using the template parameter to cgi-bin/write.cgi to write to an arbitrary file.

Exploits (1)

nomisec WORKING POC 3 stars
by MDudek-ICS · poc
https://github.com/MDudek-ICS/AntiWeb_testing-Suite

This repository contains a Python-based PoC for CVE-2017-9097, an LFI vulnerability in Anti-Web server versions 3.0.x to 3.8.x. The exploit sends a crafted POST request to read arbitrary files from the server, including sensitive configuration files like /etc/passwd and user credentials.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Anti-Web server versions 3.0.x to 3.8.x
No auth needed
Prerequisites: Network access to the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.1
EPSS 0.0373
EPSS Percentile 88.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-22
Status published
Products (11)
hoytech/antiweb 3.0.7 hms2
hoytech/antiweb 3.3.5
hoytech/antiweb 3.6.1
hoytech/antiweb 3.7.1
hoytech/antiweb 3.7.2
hoytech/antiweb 3.8.1
hoytech/antiweb 3.8.2
hoytech/antiweb 3.8.3
hoytech/antiweb 3.8.4
hoytech/antiweb 3.8.5
... and 1 more
Published Jun 16, 2017
Tracked Since Feb 18, 2026