First published: Tue Jan 03 2017(Updated: )
Directory traversal vulnerability in scgi-bin/platform.cgi on NETGEAR FVS336Gv3, FVS318N, FVS318Gv2, and SRX5308 devices with firmware before 4.3.3-8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the thispage parameter, as demonstrated by reading the /etc/shadow file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NETGEAR FVS336Gv3 | <=4.3-3.6 | |
NETGEAR FVS336Gv3 | ||
NETGEAR SRX5308 firmware | <=4.3-3.6 | |
NETGEAR SRX5308 firmware | ||
NETGEAR FVS318G firmware | <=4.3-3.6 | |
NETGEAR FVS318G firmware | ||
NETGEAR ProSafe FVS318N | <=4.3-3.6 | |
NETGEAR ProSafe FVS318N |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10106 is considered a high-severity vulnerability due to its potential for unauthorized file access.
To fix CVE-2016-10106, upgrade the firmware of affected NETGEAR devices to version 4.3.3-8 or later.
The affected NETGEAR devices include FVS336Gv3, FVS318N, FVS318Gv2, and SRX5308 with firmware versions prior to 4.3.3-8.
CVE-2016-10106 enables a directory traversal attack, allowing authenticated users to read arbitrary files.
The exploitation of CVE-2016-10106 involves the use of the 'thispage' parameter with dot-dot-slash ('..') sequences.