On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is no access control for info.html, wancfg.cmd, rtroutecfg.cmd, arpview.cmd, cpuview.cmd, memoryview.cmd, statswan.cmd, statsatm.cmd, scsrvcntr.cmd, scacccntr.cmd, logview.cmd, voicesipview.cmd, usbview.cmd, wlmacflt.cmd, wlwds.cmd, wlstationlist.cmd, HPNAShow.cmd, HPNAView.cmd, qoscls.cmd, qosqueue.cmd, portmap.cmd, scmacflt.cmd, scinflt.cmd, scoutflt.cmd, certlocal.cmd, or certca.cmd.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2017/Jul/26 | Mailing List Third Party Advisory |
http://seclists.org/fulldisclosure/2017/Jul/26 | Mailing List Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2017-07-24 00:29
Updated : 2025-04-20 01:37
NVD link : CVE-2017-11589
Mitre link : CVE-2017-11589
CVE.ORG link : CVE-2017-11589
JSON object : View
Products Affected
cisco
- residential_gateway_firmware
- residential_gateway
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')