CVE-2020-12447
Onkyo TX-NR585 Web Interface - Directory Traversal
Record summary
CVE-2020-12447 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
A Local File Inclusion (LFI) issue on Onkyo TX-NR585 1000-0000-000-0008-0000 devices allows remote unauthenticated users on the network to read sensitive files via %2e%2e%2f directory traversal, as demonstrated by reading /etc/shadow.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHOnkyo TX-NR585 Web Interface - Directory TraversalCVSS 7.5
Onkyo TX-NR585 1000-0000-000-0008-0000 devices allows remote unauthenticated users on the network to read sensitive files via %2e%2e%2f directory traversal and local file inclusion.
Impact
An attacker can access sensitive files on the system, potentially leading to unauthorized access, information disclosure, or further exploitation.
Remediation
Apply the latest firmware update provided by the vendor to fix the directory traversal vulnerability.
Source: ProjectDiscovery