First published: Tue Jan 03 2017(Updated: )
Directory traversal vulnerability in scgi-bin/platform.cgi on NETGEAR FVS336Gv3, FVS318N, FVS318Gv2, and SRX5308 devices with firmware before 4.3.3-8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the thispage parameter, as demonstrated by reading the /etc/shadow file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear Fvs336gv3 Firmware | <=4.3-3.6 | |
NETGEAR FVS336Gv3 | ||
Netgear Srx5308 Firmware | <=4.3-3.6 | |
NETGEAR SRX5308 | ||
Netgear Fvs318gv2 Firmware | <=4.3-3.6 | |
Netgear Fvs318gv2 | ||
Netgear Fvs318n Firmware | <=4.3-3.6 | |
Netgear Fvs318n |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.