CVE-2009-2258

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
30/06/2009
Last modified:
09/04/2025

Description

Directory traversal vulnerability in cgi-bin/webcm in the administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to list arbitrary directories via a .. (dot dot) in the nextpage parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:netgear:dg632_firmware:3.4.0_ap:*:*:*:*:*:*:*
cpe:2.3:h:netgear:dg632:-:*:*:*:*:*:*:*