CVE-2018-9010

HIGH

Intelbras Tip200 Firmware - Path Traversal

Title source: rule
STIX 2.1

Description

Intelbras TELEFONE IP TIP200/200 LITE 60.0.75.29 devices allow remote authenticated admins to read arbitrary files via the /cgi-bin/cgiServer.exx page parameter, aka absolute path traversal. In some cases, authentication can be achieved via the admin account with its default admin password.

Exploits (1)

exploitdb WORKING POC
by anhax0r · pythonwebappshardware
https://www.exploit-db.com/exploits/44317

Scores

CVSS v3 7.2
EPSS 0.1009
EPSS Percentile 93.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22
Status published
Products (2)
intelbras/tip200_firmware 60.0.75.29
intelbras/tip200lite_firmware 60.0.75.29
Published Mar 25, 2018
Tracked Since Feb 18, 2026