CVE-2017-6190

Directory traversal vulnerability in the web interface on the D-Link DWR-116 device with firmware before V1.05b09 allows remote attackers to read arbitrary files via a .. (dot dot) in a "GET /uir/" request.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:dlink:dwr-116_firmware:v1.01\(eu\):*:*:*:*:*:*:*
cpe:2.3:o:dlink:dwr-116_firmware:v1.00\(cp\)b10:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dwr-116_firmware:v1.05\(au\):*:*:*:*:*:*:*
OR cpe:2.3:h:dlink:dwr-116a1:-:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dwr-116:-:*:*:*:*:*:*:*

Information

Published : 2017-04-10 07:59

Updated : 2017-08-15 18:29


NVD link : CVE-2017-6190

Mitre link : CVE-2017-6190


JSON object : View

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Advertisement

dedicated server usa

Products Affected

dlink

  • dwr-116_firmware
  • dwr-116a1
  • dwr-116