CVE-2014-2962: Path Traversal
Published Jun 19, 2014
·Updated
Absolute path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware before 1.00.08 allows remote attackers to read arbitrary files via a full pathname in the getpage parameter.
Affected Software
3 affected components
Belkin N150 F9k1009 Firmware<=1.00.07
Belkin N150 F9k1009 Firmware=1.00.01
Belkin N150 F9K1009=v1
Remediation
Patch Available
Event History
Jun 19, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-2962?
The severity of CVE-2014-2962 is considered to be medium due to its potential for unauthorized file access.
2
How do I fix CVE-2014-2962?
To fix CVE-2014-2962, upgrade the Belkin N150 F9K1009 router firmware to version 1.00.08 or later.
3
What systems are affected by CVE-2014-2962?
CVE-2014-2962 affects the Belkin N150 F9K1009 router with firmware versions prior to 1.00.08.
4
Can CVE-2014-2962 allow remote exploitation?
Yes, CVE-2014-2962 allows remote attackers to exploit the vulnerability and read arbitrary files on the affected router.
5
What type of vulnerability is CVE-2014-2962?
CVE-2014-2962 is classified as an absolute path traversal vulnerability.