CVE-2016-10106: Path Traversal
Directory traversal vulnerability in scgi-bin/platform.cgi on NETGEAR FVS336Gv3, FVS318N, FVS318Gv2, and SRX5308 devices with firmware before 4.3.3-8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the thispage parameter, as demonstrated by reading the /etc/shadow file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10106?
CVE-2016-10106 is considered a high-severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2016-10106?
To fix CVE-2016-10106, upgrade the firmware of affected NETGEAR devices to version 4.3.3-8 or later.
Which NETGEAR devices are affected by CVE-2016-10106?
The affected NETGEAR devices include FVS336Gv3, FVS318N, FVS318Gv2, and SRX5308 with firmware versions prior to 4.3.3-8.
What type of attack does CVE-2016-10106 enable?
CVE-2016-10106 enables a directory traversal attack, allowing authenticated users to read arbitrary files.
What parameters are involved in the CVE-2016-10106 exploitation?
The exploitation of CVE-2016-10106 involves the use of the 'thispage' parameter with dot-dot-slash ('..') sequences.