S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2010-2307 Scanner

CVE-2010-2307 scanner - Directory Traversal vulnerability in Motorola SURFBoard SBV6120E

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.5k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
4
Vulnerabilities Found
confirmed findings
References
CVECVE-2010-2307
5.0
CVSS

Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHPC allow remote attackers to read arbitrary files via (1) "//" (multiple leading slash), (2) ../ (dot dot) sequences, and encoded dot dot sequences in a URL request.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Motorola SURFBoard SBV6120E is a cable modem utilized in households and small businesses to provide internet connectivity. This modem comes with a range of features that include high-speed downstream and upstream data transfer rates, allowing for faster data transmission over the internet. By connecting to the DOCSIS 3.0 network, the device can offer IPv6 segmentation and numerous other network services, making it an excellent choice for those wishing for a robust internet connection. 

A vulnerability code, CVE-2010-2307, was discovered in the Motorola SURFBoard SBV6120E. This bug allows remote attackers to read arbitrary files through a webserver running firmware SBV6X2X-1.0.0.5-SCM-02-SHPC using directory traversal techniques, specifically "//" and "../". As a result, attackers can gain unauthorized access to system files, client information, and any other accessible data on the device. Exploiting this vulnerability can have disastrous consequences on devices, exposing sensitive data to malicious actors.

If exploited, the vulnerability can compromise entire networks, leaving devices and users at risk of data breaches. Attackers can use this vulnerability to gather sensitive information, such as user credentials and personally identifiable information, to launch further attacks. This may lead to financial loss, damage to reputation, and even worse harm to both individuals and organizations.

Fortunately, s4e.io has highly advanced tools and features that enable individuals to protect their digital assets and stay safe from vulnerabilities like CVE-2010-2307. These features will enable those who read this article to safeguard their digital assets easily and fast. As such, the platform is an excellent choice for those seeking to keep their digital assets secure effectively and efficiently.

 

REFERENCES

Solution Advice

To reduce the risk of exploitation, users can take the following precautions:

  • Monitor the device's HTTP/HTTPS traffic for unexpected activity 
  • Implement and regularly update security protocols on the modem 
  • Block traffic containing malicious files or directory traversal attempts 
  • Limit access to the device's sensitive information by properly configuring its permissions 
  • Use firmware with security updates enabled.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2010-2307 scanner - Directory Traversal vulnerability in Motorola SURFBoard SBV6120E S4E