Description
A directory traversal vulnerability exists in Linksys router's web interface (tested on the E1500 model firmware versions 1.0.00, 1.0.04, and 1.0.05), specifically in the /apply.cgi endpoint. Authenticated attackers can exploit the next_page POST parameter to access arbitrary files outside the intended web root by injecting traversal sequences. This allows exposure of sensitive system files and configuration data.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
1.0.00
1.0.04
1.0.05
Credits
Michael Messner
References
web.archive.org/...4015/http://www.s3cur1ty.de/m1adv2013-004
www.exploit-db.com/exploits/24475
raw.githubusercontent.com/...http/linksys_e1500_traversal.rb
raw.githubusercontent.com/...http/linksys_e1500_traversal.rb
www.exploit-db.com/exploits/24475
web.archive.org/...4015/http://www.s3cur1ty.de/m1adv2013-004
www.vulncheck.com/...s/linksys-legacy-routers-path-traversal