Vulnerability Intelligence Report
Netis Netcore Router Backup param.file.tgz information disclosure
CVE-2023-0113
A vulnerability was found in Netis Netcore Router up to 2.2.6. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file param.file.tgz of the component Backup Handler. The manipulation leads to information disclosure. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-217591.
No Active Exploit Signals
CVSS Base Score
5.3
MEDIUM
Exploitability:3.9
Impact Score:1.5
EPSS Probability:0.78%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-200 ↗CWE-200 Information Disclosure
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Netis | Netcore Router | 2.2.0 (affected), 2.2.1 (affected), 2.2.2 (affected), 2.2.3 (affected), 2.2.4 (affected), 2.2.5 (affected), 2.2.6 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.779%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | VulDB · Researcher · Switzerland |
| Reserved | 2023-01-07T08:16:56 |
| Published | 2023-01-07T08:22:36 |
| Last Updated | 2024-08-02T05:02:44 |
Community Chatter & Buzz