First published: Thu Jun 19 2014(Updated: )
Absolute path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware before 1.00.08 allows remote attackers to read arbitrary files via a full pathname in the getpage parameter.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Belkin N150 F9K1009 Firmware | <=1.00.07 | |
Belkin N150 F9K1009 Firmware | =1.00.01 | |
Belkin N150 F9K1009 Firmware | =v1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-2962 is considered to be medium due to its potential for unauthorized file access.
To fix CVE-2014-2962, upgrade the Belkin N150 F9K1009 router firmware to version 1.00.08 or later.
CVE-2014-2962 affects the Belkin N150 F9K1009 router with firmware versions prior to 1.00.08.
Yes, CVE-2014-2962 allows remote attackers to exploit the vulnerability and read arbitrary files on the affected router.
CVE-2014-2962 is classified as an absolute path traversal vulnerability.