PT-2013-5452 · Hot · Hotbox Router

Published

2013-12-30

·

Updated

2013-12-30

·

CVE-2013-5219

CVSS v2.0

3.3

Low

VectorAV:A/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions HOT HOTBOX router version 2.1.11
Description A directory traversal issue allows remote attackers to read arbitrary files by including a .. (dot dot) in a URI. For example, a request for "/etc/passwd" can be used to exploit this issue.
Recommendations For version 2.1.11, consider restricting access to sensitive files and directories until a patch is available. As a temporary workaround, avoid using URI requests that include .. (dot dot) to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-5219

Affected Products

Hotbox Router