CVE-2017-7577 describes a critical directory traversal vulnerability in XiongMai uc-httpd, allowing unauthenticated attackers to read arbitrary files via specially crafted HTTP GET requests. With a CVSS score of 9.8, this flaw presents a high risk due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, its high FAUCET Risk Score of 83/100 and mentions in security media like SecurityWeek indicate its significance. Despite its age, there is no public exploit code available in Metasploit, Nuclei, or ExploitDB, suggesting limited active exploitation or public tooling.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:xiongmaitech:uc-httpd:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.