On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is no access control for info.html, wancfg.cmd, rtroutecfg.cmd, arpview.cmd, cpuview.cmd, memoryview.cmd, statswan.cmd, statsatm.cmd, scsrvcntr.cmd, scacccntr.cmd, logview.cmd, voicesipview.cmd, usbview.cmd, wlmacflt.cmd, wlwds.cmd, wlstationlist.cmd, HPNAShow.cmd, HPNAView.cmd, qoscls.cmd, qosqueue.cmd, portmap.cmd, scmacflt.cmd, scinflt.cmd, scoutflt.cmd, certlocal.cmd, or certca.cmd.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2017/Jul/26 | Mailing List Third Party Advisory |
http://seclists.org/fulldisclosure/2017/Jul/26 | Mailing List Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 03:08
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/fulldisclosure/2017/Jul/26 - Mailing List, Third Party Advisory |
Information
Published : 2017-07-24 00:29
Updated : 2024-11-21 03:08
NVD link : CVE-2017-11589
Mitre link : CVE-2017-11589
CVE.ORG link : CVE-2017-11589
JSON object : View
Products Affected
cisco
- residential_gateway
- residential_gateway_firmware
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')