CVE-2017-12943
D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to read passwords via a model/__show_info.php?REQUIRE_FILE= absolute path traversal attack, as demonstrated by discovering the admin password.
- Affected products
- Dir-600M
- Dlink dir-600 b1 Firmware
- = 2.01
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 39.2% (99th percentile)
- Weakness
- CWE-22
- NVD status
- Modified
- Published
- 2017-08-18
CVE-2017-12943 at NVD
5 known exploits for CVE-2017-12943
Proof-of-concept code and exploit modules indexed by Sploitus