← Vulnerability feed

Vulnerability record · CVE-2017-9833 · published 24 June 2017

CVE-2017-9833: Boa wapopen path traversal via FILECAMERA reads files as root

Boa · Boa

A path traversal flaw is reported in /cgi-bin/wapopen in Boa 0.94.14rc21, where the FILECAMERA GET variable accepts "../.." sequences and can read files with root privileges. The record notes that multiple third parties dispute this as a Boa issue, stating Boa ships no wapopen program or FILECAMERA handling and that the flaw is likely a system-integrator or camera-specific problem. The practical risk is unauthenticated disclosure of sensitive files on affected deployments.

7.5 CVSS 3.1 High EPSS 68% · top 0.7% CWE-22 · Path traversal
7.5CVSS 3.1 base score, v2 7.8
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privileges. NOTE: multiple third parties report that this is a system-integrator issue (e.g., a vulnerability on one type of camera) because Boa does not include any wapopen program or any code to read a FILECAMERA variable.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated remote file read with root privileges and a high EPSS score, though the affected component's presence is disputed and no KEV listing exists.

What it is

A path traversal flaw is reported in /cgi-bin/wapopen in Boa 0.94.14rc21, where the FILECAMERA GET variable accepts "../.." sequences and can read files with root privileges. The record notes that multiple third parties dispute this as a Boa issue, stating Boa ships no wapopen program or FILECAMERA handling and that the flaw is likely a system-integrator or camera-specific problem. The practical risk is unauthenticated disclosure of sensitive files on affected deployments.

Impact

An attacker can read arbitrary files with root privileges, exposing credentials, configuration and other sensitive data. There is no integrity or availability impact in the CVSS vector; the gain is information disclosure.

Attack surface

Reachable over the network through a GET request to /cgi-bin/wapopen with a crafted FILECAMERA value. The CVSS vector shows no privileges required and no user interaction, so it is unauthenticated and remotely triggerable where the endpoint exists.

Exploitation

Public exploit references exist (Exploit-DB 42290 and a Pastebin entry), and EPSS is 0.68464 (99.3rd percentile), indicating high predicted exploitation activity. It is not listed in CISA KEV, so no confirmed in-the-wild use is recorded here.

What to do

  • Patch or replace the affected Boa-based firmware/device; apply the vendor's current firmware if one exists.
  • If no fix is available, block or disable access to /cgi-bin/wapopen and remove the wapopen CGI if it is not required.
  • Restrict management and CGI interfaces to trusted networks and require authentication in front of them.
  • Run the web service with least privilege rather than root, and validate/normalize FILECAMERA input to reject traversal sequences.
  • Confirm whether the disputed component is actually present; if Boa itself lacks wapopen, treat this as a system-integrator/camera issue and remediate at that layer.

Detection

  • Search web logs for GET requests to /cgi-bin/wapopen containing FILECAMERA values with ../ or ..%2f sequences.
  • Alert on access to /cgi-bin/wapopen from untrusted or unexpected source addresses.
  • Monitor for reads of sensitive files (for example /etc/passwd, /etc/shadow) correlated with web server process activity.
  • Inventory devices running Boa 0.94.14rc21 or embedding wapopen to identify exposed instances.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://pastebin.com/raw/rt7LJvyF ExploitThird Party Advisory
https://www.exploit-db.com/exploits/42290/ ExploitThird Party AdvisoryVDB Entry
https://pastebin.com/raw/rt7LJvyF ExploitThird Party Advisory
https://www.exploit-db.com/exploits/42290/ ExploitThird Party AdvisoryVDB Entry

Track CVE-2017-9833 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-44117Boa sql injection vulnerabilityBoa 0.94.14rc21 is vulnerable to SQL Injection via username. NOTE: the is disputed by multiple third parties because Boa does not ship with any suppo…EPSS 0.73%9.8CVE-2018-21027Boa memory buffer overflow vulnerabilityBoa through 0.94.14rc21 allows remote attackers to trigger an out-of-memory (OOM) condition because malloc is mishandled.EPSS 2.4%7.5CVE-2021-33558Boa vulnerabilityBoa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, log.html, …EPSS 12%7.5CVE-2018-21028Boa vulnerabilityBoa through 0.94.14rc21 allows remote attackers to trigger a memory leak because of missing calls to the free function.EPSS 2.1%7.5CVE-2016-9564Boa improper input validation vulnerabilityBuffer overflow in send_redirect() in Boa Webserver 0.92r allows remote attackers to DoS via an HTTP GET request requesting a long URI with only '/' …EPSS 1.4%5.3CVE-2022-45956Boa incorrect authorization vulnerabilityBoa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone to bypass …EPSS 0.82%5.0CVE-2009-4496Boa improper input validation vulnerabilityBoa 0.94.14rc21 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title,…EPSS 12%9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%

Source: NIST National Vulnerability Database (record CVE-2017-9833), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.