Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2017-17309 PoC — Huawei HG255s-10 路径遍历漏洞

Source
Associated Vulnerability
Title: Huawei HG255s-10 路径遍历漏洞 (CVE-2017-17309)
Description:Huawei HG255s-10 V100R001C163B025SP02 has a path traversal vulnerability due to insufficient validation of the received HTTP requests, a remote attacker may access the local files on the device without authentication.
Description
🚀 Server Directory Traversal at Huawei HG255s ☄️ - CVE-2017-17309 🚀
Readme
### Server Directory Traversal at Huawei HG255s - CVE-2017-17309

![huawei](https://user-images.githubusercontent.com/15425071/31989903-489b48fa-b97c-11e7-8698-ea794276d08a.png)

<p align="center">
  <img src="https://cdn.rawgit.com/sindresorhus/awesome/d7305f38d29fed78fa85652e3a63e154dd8e8829/media/badge.svg"> <img src="https://img.shields.io/github/stars/exploit-labs/huawei_hg255s_exploit?style=social"> <img src="https://img.shields.io/github/forks/exploit-labs/huawei_hg255s_exploit?style=social"> <img src="https://img.shields.io/github/repo-size/exploit-labs/huawei_hg255s_exploit"> <img src="https://img.shields.io/github/license/exploit-labs/huawei_hg255s_exploit"> <img src="https://img.shields.io/github/issues/detail/author/exploit-labs/huawei_hg255s_exploit/1">
</p>

##### Letter of Thanks

![letterofthanks](https://user-images.githubusercontent.com/15425071/31990117-d75894e4-b97c-11e7-8275-6909a6b47b48.png)

#### Exploit Title: [Server Directory Traversal at Huawei HG255s]

#### Exploit Author: [Ismail Tasdelen]

#### CVE : CVE-2017-17309

#### Vendor Homepage: [[www.huawei.com](https://www.huawei.com)]
 
#### Software Link: [Not published this modem just used by Turkey]
 
#### Version: [V100R001C163B025SP02]

![cve-2017-17309](https://user-images.githubusercontent.com/15425071/39086966-c989b58a-45a1-11e8-9a7e-abbb34393ba9.PNG)

##### Finding Vulnerabilities and Approved Exploits

* [Server Directory Traversal at Huawei HG255s - 1](https://github.com/ismailtasdelen/huawei_hg255s_exploit/blob/master/exploit/huawei_hg255_exploit_1.txt)

* [Server Directory Traversal at Huawei HG255s - 2](https://github.com/ismailtasdelen/huawei_hg255s_exploit/blob/master/exploit/huawei_hg255_exploit_2.txt)

* [Server Directory Traversal at Huawei HG255s - 3](https://github.com/ismailtasdelen/huawei_hg255s_exploit/blob/master/exploit/huawei_hg255_exploit_3.txt)

##### References :

* https://www.vulnerability-lab.com/get_content.php?id=2099
* https://www.vulnerability-lab.com/get_content.php?id=2100
* https://cxsecurity.com/issue/WLB-2017120035
* https://hackertor.com/2017/12/06/huawei-hg255s-server-directory-traversal/
* https://www.exploit-database.net/?id=94806
* https://github.com/ismailtasdelen/huawei_hg255s_exploit
* http://www.huawei.com/en/psirt/security-notices/huawei-sn-20170911-01-hg255s-en
* https://nvd.nist.gov/vuln/detail/CVE-2017-17309
* https://www.cvedetails.com/cve/CVE-2017-17309/
* https://vuldb.com/?id.119545
* https://vulners.com/cve/CVE-2017-17309
* http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17309
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →