
Full Disclosure mailing list archives
SSD Advisory – Geneko Routers Unauthenticated Path Traversal
From: Maor Shwartz <maors () beyondsecurity com>
Date: Sun, 16 Jul 2017 11:45:04 +0300
Hi, SSD Advisory – Geneko Routers Unauthenticated Path Traversal *Link*: https://blogs.securiteam.com/index.php/archives/3317 *Twitter*: @SecuriTeam_SSD *Vulnerability Summary* The following advisory describes a Unauthenticated Path Traversal vulnerability found in Geneko GWR routers series. Geneko GWG is compact and cost effective communications solution that provides cellular capabilities for fixed and mobile applications such as data acquisition, smart metering, remote monitoring and management. GWG supports a variety of radio bands options on 2G, 3G and 4G cellular technologies. *Credit* An independent security researcher, Patrik Fehrenbach (@ITSecurityguard), has reported this vulnerability to Beyond Security’s SecuriTeam Secure Disclosure program *Vendor response* We have informed Geneko of the vulnerability on the 28th of May 2017, the last email we received from them was on the 7th of June 2017. We have no further updates from Geneko regarding the availability of a patch or a workaround for the vulnerability. -- Thanks Maor Shwartz GPG Key ID: 93CC36E2DE7FF514
Attachment:
SSD Advisory – Geneko Routers Unauthenticated Path Traversal – SecuriTeam Blogs.pdf
Description:
_______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/
Current thread:
- SSD Advisory – Geneko Routers Unauthenticated Path Traversal Maor Shwartz (Jul 17)