Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4m2v-gmf9-56qj

Опубликовано: 26 июн. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

A path traversal vulnerability exists in the web management interface of D-Link DSL-2730U, DSL-2750U, and DSL-2750E ADSL routers with firmware versions IN_1.02, SEA_1.04, and SEA_1.07. The vulnerability is due to insufficient input validation on the getpage parameter within the /cgi-bin/webproc CGI script. This flaw allows an unauthenticated remote attacker to perform path traversal attacks by supplying crafted requests, enabling arbitrary file read on the affected device.

A path traversal vulnerability exists in the web management interface of D-Link DSL-2730U, DSL-2750U, and DSL-2750E ADSL routers with firmware versions IN_1.02, SEA_1.04, and SEA_1.07. The vulnerability is due to insufficient input validation on the getpage parameter within the /cgi-bin/webproc CGI script. This flaw allows an unauthenticated remote attacker to perform path traversal attacks by supplying crafted requests, enabling arbitrary file read on the affected device.

EPSS

Процентиль: 46%
0.00232
Низкий

8.7 High

CVSS4

Дефекты

CWE-20
CWE-22

Связанные уязвимости

nvd
8 месяцев назад

A path traversal vulnerability exists in the web management interface of D-Link DSL-2730U, DSL-2750U, and DSL-2750E ADSL routers with firmware versions IN_1.02, SEA_1.04, and SEA_1.07. The vulnerability is due to insufficient input validation on the getpage parameter within the /cgi-bin/webproc CGI script. This flaw allows an unauthenticated remote attacker to perform path traversal attacks by supplying crafted requests, enabling arbitrary file read on the affected device. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-04 UTC.

CVSS3: 7.5
fstec
больше 13 лет назад

Уязвимость веб-интерфейса управления микропрограммного обеспечения маршрутизаторов D-Link DSL-2730U, DSL-2750U и DSL-2750E, позволяющая нарушителю читать произвольные файлы

EPSS

Процентиль: 46%
0.00232
Низкий

8.7 High

CVSS4

Дефекты

CWE-20
CWE-22