A Local File Inclusion (LFI) issue on Onkyo TX-NR585 1000-0000-000-0008-0000 devices allows remote unauthenticated users on the network to read sensitive files via %2e%2e%2f directory traversal, as demonstrated by reading /etc/shadow.
References
| Link | Resource |
|---|---|
| https://blog.spookysec.net/onkyo-lfi/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Information
Published : 2020-04-28 20:15
Updated : 2020-05-11 06:23
NVD link : CVE-2020-12447
Mitre link : CVE-2020-12447
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
onkyo
- tx-nr585
- tx-nr585_firmware


