Vulnerability Description
Geneko GWR routers allow directory traversal sequences starting with a /../ substring, as demonstrated by unauthenticated read access to the configuration file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Geneko | Gwr352 3G Router Firmware | - |
| Geneko | Gwr352 3G Router | - |
| Geneko | Gwr352Wv Wide Voltage 3G Router Firmware | - |
| Geneko | Gwr352Wv Wide Voltage 3G Router | - |
| Geneko | Gwr252 Edge Router Firmware | - |
| Geneko | Gwr252 Edge Router | - |
| Geneko | Gwr202 Gprs Router Firmware | - |
| Geneko | Gwr202 Gprs Router | - |
Related Weaknesses (CWE)
References
- https://blogs.securiteam.com/index.php/archives/3317#more-3317ExploitTechnical Description
- https://blogs.securiteam.com/index.php/archives/3317#more-3317ExploitTechnical Description
FAQ
What is CVE-2017-11456?
CVE-2017-11456 is a vulnerability with a CVSS score of 7.5 (HIGH). Geneko GWR routers allow directory traversal sequences starting with a /../ substring, as demonstrated by unauthenticated read access to the configuration file.
How severe is CVE-2017-11456?
CVE-2017-11456 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-11456?
Check the references section above for vendor advisories and patch information. Affected products include: Geneko Gwr352 3G Router Firmware, Geneko Gwr352 3G Router, Geneko Gwr352Wv Wide Voltage 3G Router Firmware, Geneko Gwr352Wv Wide Voltage 3G Router, Geneko Gwr252 Edge Router Firmware.