High severity7.5NVD Advisory· Published Apr 10, 2017· Updated May 13, 2026
CVE-2017-6190
CVE-2017-6190
Description
Directory traversal vulnerability in the web interface on the D-Link DWR-116 device with firmware before V1.05b09 allows remote attackers to read arbitrary files via a .. (dot dot) in a "GET /uir/" request.
Affected products
3cpe:2.3:o:dlink:dwr-116_firmware:v1.00\(cp\)b10:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:dlink:dwr-116_firmware:v1.00\(cp\)b10:*:*:*:*:*:*:*
- cpe:2.3:o:dlink:dwr-116_firmware:v1.01\(eu\):*:*:*:*:*:*:*
- cpe:2.3:o:dlink:dwr-116_firmware:v1.05\(au\):*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- cxsecurity.com/blad/WLB-2017040033nvdThird Party Advisory
- www.securityfocus.com/bid/97620nvd
- www.exploit-db.com/exploits/41840/nvd
News mentions
0No linked articles in our index yet.