Absolute path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware before 1.00.08 allows remote attackers to read arbitrary files via a full pathname in the getpage parameter.
Loading...
Loading...
Score elevated to 9.0 because EPSS predicts 89% probability of exploitation within the next 30 days (top 0.5% of all CVEs). Confidence: see factors.
Absolute path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware before 1.00.08 allows remote attackers to read arbitrary files via a full pathname in the getpage parameter.
June 19, 2014
May 6, 2026
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
Working exploit code is in the public domain (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
Belkin N150 Router 1.00.08/1.00.09 - Directory Traversal
Open source ↗Belkin N150 Router 1.00.08/1.00.09 - Path Traversal
Open source ↗See which npm, PyPI, Go, and Maven packages are affected by CVE-2014-2962
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.