CVE-2017-11589

On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is no access control for info.html, wancfg.cmd, rtroutecfg.cmd, arpview.cmd, cpuview.cmd, memoryview.cmd, statswan.cmd, statsatm.cmd, scsrvcntr.cmd, scacccntr.cmd, logview.cmd, voicesipview.cmd, usbview.cmd, wlmacflt.cmd, wlwds.cmd, wlstationlist.cmd, HPNAShow.cmd, HPNAView.cmd, qoscls.cmd, qosqueue.cmd, portmap.cmd, scmacflt.cmd, scinflt.cmd, scoutflt.cmd, certlocal.cmd, or certca.cmd.
References
Link Resource
http://seclists.org/fulldisclosure/2017/Jul/26 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2017/Jul/26 Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:cisco:residential_gateway_firmware:ddr2200b-na-annexa-fcc-v00.00.03.45.4e:*:*:*:*:*:*:*
cpe:2.3:o:cisco:residential_gateway_firmware:ddr2201v1-na-annexa-fcc-v00.00.03.28.3:*:*:*:*:*:*:*
cpe:2.3:h:cisco:residential_gateway:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:08

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2017/Jul/26 - Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2017/Jul/26 - Mailing List, Third Party Advisory

Information

Published : 2017-07-24 00:29

Updated : 2024-11-21 03:08


NVD link : CVE-2017-11589

Mitre link : CVE-2017-11589

CVE.ORG link : CVE-2017-11589


JSON object : View

Products Affected

cisco

  • residential_gateway
  • residential_gateway_firmware
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')