Vulnerability Description
Technicolor DPC3928AD DOCSIS devices allow remote attackers to read arbitrary files via a request starting with "GET /../" on TCP port 4321.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Dpc3928Ad Docsis Wireless Router Firmware | - |
| Cisco | Dpc3928Ad Docsis Wireless Router | - |
Related Weaknesses (CWE)
References
- https://blogs.securiteam.com/index.php/archives/2911#more-2911ExploitThird Party Advisory
- https://blogs.securiteam.com/index.php/archives/2911#more-2911ExploitThird Party Advisory
FAQ
What is CVE-2017-11502?
CVE-2017-11502 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Technicolor DPC3928AD DOCSIS devices allow remote attackers to read arbitrary files via a request starting with "GET /../" on TCP port 4321.
How severe is CVE-2017-11502?
CVE-2017-11502 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-11502?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Dpc3928Ad Docsis Wireless Router Firmware, Cisco Dpc3928Ad Docsis Wireless Router.