peter bassill · operator
$ cve CVE-2017-11456 JSON

CVE-2017-11456 EXPLOIT

7.5
HIGH · CVSS 3.0 · EPSS 8.8% (pctl 95)

Patch early

A public exploit exists.

Description

Geneko GWR routers allow directory traversal sequences starting with a /../ substring, as demonstrated by unauthenticated read access to the configuration file.

Scoring

CVSS7.5 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS8.81% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2017-07-19
Last modified2026-06-17

Affected (8)

VendorProduct
genekogwr202 gprs router
genekogwr202 gprs router firmware
genekogwr252 edge router
genekogwr252 edge router firmware
genekogwr352 3g router
genekogwr352 3g router firmware
genekogwr352wv wide voltage 3g router
genekogwr352wv wide voltage 3g router firmware

Public exploits

SourceTitleDate
exploit-dbGeneko Routers - Path Traversal2017-07-16

References

→ the Explorer  ·  watch your stack  ·  NVD