CVE-2018-9010: Path Traversal
Published Mar 25, 2018
·Updated
Intelbras TELEFONE IP TIP200/200 LITE 60.0.75.29 devices allow remote authenticated admins to read arbitrary files via the /cgi-bin/cgiServer.exx page parameter, aka absolute path traversal. In some cases, authentication can be achieved via the admin account with its default admin password.
Affected Software
8 affected components
Intelbras Tip200 Firmware=60.0.75.29
Intelbras TIP200
Intelbras Tip200lite Firmware=60.0.75.29
Intelbras TIP200LITE
All of the following
Intelbras Tip200 Firmware=60.0.75.29
Intelbras TIP200
All of the following
Intelbras Tip200lite Firmware=60.0.75.29
Intelbras TIP200LITE
Event History
Mar 25, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-9010?
The severity of CVE-2018-9010 is high with a CVSS score of 7.2.
2
How can remote authenticated admins exploit CVE-2018-9010?
Remote authenticated admins can exploit CVE-2018-9010 by reading arbitrary files via the /cgi-bin/cgiServer.exx page parameter.
3
Is the admin account affected by CVE-2018-9010?
Yes, in some cases, authentication can be achieved via the admin account with its default admin password.
4
Is Intelbras TIP200 affected by CVE-2018-9010?
No, Intelbras TIP200 is not affected by CVE-2018-9010.
5
How can I fix CVE-2018-9010?
To fix CVE-2018-9010, update the firmware to version 60.0.75.29 or above.