S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2017-9833 Scanner

CVE-2017-9833 scanner - Improper Access Control vulnerability in Boa

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-9833
7.5
CVSS

/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privileges. NOTE: multiple third parties report that this is a system-integrator issue (e.g., a vulnerability on one type of camera) because Boa does not include any wapopen program or any code to read a FILECAMERA variable.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Boa is a lightweight HTTP server that is used for embedded network devices such as routers, switches, and IP cameras. It is designed to optimize memory usage and be easily integrated into small, resource-constrained systems. The purpose of Boa is to allow these devices to serve web pages to users for configuration, monitoring, and maintenance purposes. It is a popular choice among developers due to its open-source nature and ease of use. 

One vulnerability that was detected in Boa is CVE-2017-9833. This vulnerability allows attackers to inject "../.." using the FILECAMERA variable sent through the GET method. This allows unauthorized access to the root directory of the device, granting the attacker escalated privileges. Though Boa does not include any wapopen program or code to read the FILECAMERA variable, third-party integrators may have used this vulnerable code in their implementation of Boa on a specific device, leading to the vulnerability. 

If exploited, this vulnerability could allow attackers to modify important system files, steal sensitive user information, and potentially even take control of the device. The attack becomes especially dangerous when the device is connected to a larger network, as the attacker could then use the device as a pivot point to launch attacks against other systems on the network. This makes it all the more important for users to be aware of this vulnerability and take measures to mitigate it. 

Security is paramount in the modern digital landscape, and familiarity with vulnerabilities in their digital assets is a must-have skill for individuals and organizations alike. With the pro features of the s4e.io platform, users can quickly and easily learn about vulnerabilities in their systems, gain insights into how to protect themselves, and stay up-to-date with the latest security news and trends. By prioritizing security, users can ensure the safety and privacy of themselves and their data.

 

REFERENCES

Solution Advice

To protect against CVE-2017-9833, one can take the following precautions:

  • Verify that the Boa version used on the device is not affected by the vulnerability.
  • Install any available patches or updates for Boa that address the vulnerability.
  • Ensure that the device is protected by a strong login password and that remote access to the device is secured.
  • Restrict network access to the device to only trusted sources.
  • Monitor device logs and network traffic for any suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.