← Vulnerability feed

Vulnerability record · CVE-2017-6564 · published 1 May 2017

CVE-2017-6564: Franklinfueling ts-550 evo firmware missing authorization vulnerability

Franklinfueling · Ts 550 Evo Firmware

On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the Guest user, which contains the lowest privileges, can post to the idSourceFileName parameter found within the /download directory. This ability allows for an attacker to download sensitive system files from the host machine such as databases which contain information that can aid in further attacks.

6.5 CVSS 3.0 Medium EPSS 0.82% · top 44.6% CWE-862 · Missing authorization
6.5CVSS 3.0 base score, v2 4.0
0.82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the Guest user, which contains the lowest privileges, can post to the idSourceFileName parameter found within the /download directory. This ability allows for an attacker to download sensitive system files from the host machine such as databases which contain information that can aid in further attacks.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-6564 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-7248Franklinfueling ts-550 evo firmware vulnerabilityFranklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 has a hardcoded password for the roleDiag account, which…EPSS 3.8%9.8CVE-2023-5846Franklinfueling ts-550 evo firmware vulnerabilityFranklin Fueling System TS-550 versions prior to 1.9.23.8960 are vulnerable to attackers decoding admin credentials, resulting in unauthenticated acc…EPSS 0.28%8.8CVE-2017-6565Franklinfueling ts-550 evo firmware missing authorization vulnerabilityOn Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the roleDiag user, which can be obtained by exploiting CVE-2013-7247, has the ability to u…EPSS 1.0%7.5CVE-2021-46420Franklinfueling ts-550 evo firmware path traversal vulnerabilityFranklin Fueling Systems FFS TS-550 evo 2.23.4.8936 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to …EPSS 5.7%7.5CVE-2021-46421Franklinfueling ts-550 evo firmware path traversal vulnerabilityFranklin Fueling Systems FFS T5 Series 1.8.7.7299 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to ob…EPSS 6.0%5.0CVE-2013-7247Franklinfueling ts-550 evo firmware permissions and access controls vulnerabilitycgi-bin/tsaws.cgi in Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 allows remote attackers to discover…EPSS 2.6%9.9CVE-2026-84869ScreenConnect client allows unauthorized file transfer and execution in remote sessionsA flaw in the ConnectWise ScreenConnect client lets files be transferred and executed inside an active remote session without authorization or Host c…KEVEPSS 0.92%analysed7.8CVE-2022-0492Linux kernel cgroups v1 release_agent privilege escalation and container escapeThe Linux kernel's cgroup_release_agent_write in kernel/cgroup/cgroup-v1.c mishandles authorization, letting the cgroups v1 release_agent feature be …KEVEPSS 5.5%analysed

Source: NIST National Vulnerability Database (record CVE-2017-6564), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.