First published: Mon Apr 10 2017(Updated: )
Directory traversal vulnerability in the web interface on the D-Link DWR-116 device with firmware before V1.05b09 allows remote attackers to read arbitrary files via a .. (dot dot) in a "GET /uir/" request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link DWR-116 Firmware | =v1.00\(cp\)b10 | |
D-Link DWR-116 Firmware | =v1.01\(eu\) | |
D-Link DWR-116 Firmware | =v1.05\(au\) | |
D-Link DWR-116 | ||
D-Link DWR-116 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6190 is classified as a medium severity vulnerability.
To fix CVE-2017-6190, upgrade the D-Link DWR-116 firmware to version 1.05b09 or later.
CVE-2017-6190 can be exploited through a directory traversal attack, allowing unauthorized file access.
CVE-2017-6190 affects D-Link DWR-116 devices running firmware versions prior to V1.05b09.
Yes, CVE-2017-6190 allows remote attackers to read arbitrary files if exploited successfully.