Directory traversal vulnerability in the web interface on the D-Link DWR-116 device with firmware before V1.05b09 allows remote attackers to read arbitrary files via a .. (dot dot) in a "GET /uir/" request.
2017-04-10T14:59:00.263
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | dlink | dwr-116_firmware | v1.00\(cp\)b10 | Yes |
Operating System | dlink | dwr-116_firmware | v1.01\(eu\) | Yes |
Operating System | dlink | dwr-116_firmware | v1.05\(au\) | Yes |
Hardware | dlink | dwr-116 | - | No |
Hardware | dlink | dwr-116a1 | - | No |