Directory traversal vulnerability in scgi-bin/platform.cgi on NETGEAR FVS336Gv3, FVS318N, FVS318Gv2, and SRX5308 devices with firmware before 4.3.3-8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the thispage parameter, as demonstrated by reading the /etc/shadow file.
2017-01-03T06:59:00.183
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | netgear | fvs336gv3_firmware | ≤ 4.3-3.6 | Yes |
Hardware | netgear | fvs336gv3 | - | No |
Operating System | netgear | srx5308_firmware | ≤ 4.3-3.6 | Yes |
Hardware | netgear | srx5308 | - | No |
Operating System | netgear | fvs318gv2_firmware | ≤ 4.3-3.6 | Yes |
Hardware | netgear | fvs318gv2 | - | No |
Operating System | netgear | fvs318n_firmware | ≤ 4.3-3.6 | Yes |
Hardware | netgear | fvs318n | - | No |