CVE-2017-12943: Path Traversal
D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to read passwords via a model/showinfo.php?REQUIREFILE= absolute path traversal attack, as demonstrated by discovering the admin password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12943?
CVE-2017-12943 is considered a medium severity vulnerability due to its ability to allow unauthorized access to sensitive information.
How do I fix CVE-2017-12943?
To fix CVE-2017-12943, update your D-Link DIR-600 Rev Bx devices to the latest firmware version provided by D-Link.
What impact does CVE-2017-12943 have on my device?
CVE-2017-12943 allows remote attackers to exploit an absolute path traversal vulnerability and read sensitive data, including passwords.
Which devices are affected by CVE-2017-12943?
CVE-2017-12943 affects D-Link DIR-600 Rev Bx devices running v2.x firmware, specifically version 2.01.
Is CVE-2017-12943 a local or remote vulnerability?
CVE-2017-12943 is a remote vulnerability, meaning that it can be exploited from outside the local network.