Vulnerability record · CVE-2017-9833 · published 24 June 2017
CVE-2017-9833: Boa wapopen path traversal via FILECAMERA reads files as root
Boa · Boa
A path traversal flaw is reported in /cgi-bin/wapopen in Boa 0.94.14rc21, where the FILECAMERA GET variable accepts "../.." sequences and can read files with root privileges. The record notes that multiple third parties dispute this as a Boa issue, stating Boa ships no wapopen program or FILECAMERA handling and that the flaw is likely a system-integrator or camera-specific problem. The practical risk is unauthenticated disclosure of sensitive files on affected deployments.
Description
/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privileges. NOTE: multiple third parties report that this is a system-integrator issue (e.g., a vulnerability on one type of camera) because Boa does not include any wapopen program or any code to read a FILECAMERA variable.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated remote file read with root privileges and a high EPSS score, though the affected component's presence is disputed and no KEV listing exists.
What it is
A path traversal flaw is reported in /cgi-bin/wapopen in Boa 0.94.14rc21, where the FILECAMERA GET variable accepts "../.." sequences and can read files with root privileges. The record notes that multiple third parties dispute this as a Boa issue, stating Boa ships no wapopen program or FILECAMERA handling and that the flaw is likely a system-integrator or camera-specific problem. The practical risk is unauthenticated disclosure of sensitive files on affected deployments.
Impact
An attacker can read arbitrary files with root privileges, exposing credentials, configuration and other sensitive data. There is no integrity or availability impact in the CVSS vector; the gain is information disclosure.
Attack surface
Reachable over the network through a GET request to /cgi-bin/wapopen with a crafted FILECAMERA value. The CVSS vector shows no privileges required and no user interaction, so it is unauthenticated and remotely triggerable where the endpoint exists.
Exploitation
Public exploit references exist (Exploit-DB 42290 and a Pastebin entry), and EPSS is 0.68464 (99.3rd percentile), indicating high predicted exploitation activity. It is not listed in CISA KEV, so no confirmed in-the-wild use is recorded here.
What to do
- Patch or replace the affected Boa-based firmware/device; apply the vendor's current firmware if one exists.
- If no fix is available, block or disable access to /cgi-bin/wapopen and remove the wapopen CGI if it is not required.
- Restrict management and CGI interfaces to trusted networks and require authentication in front of them.
- Run the web service with least privilege rather than root, and validate/normalize FILECAMERA input to reject traversal sequences.
- Confirm whether the disputed component is actually present; if Boa itself lacks wapopen, treat this as a system-integrator/camera issue and remediate at that layer.
Detection
- Search web logs for GET requests to /cgi-bin/wapopen containing FILECAMERA values with ../ or ..%2f sequences.
- Alert on access to /cgi-bin/wapopen from untrusted or unexpected source addresses.
- Monitor for reads of sensitive files (for example /etc/passwd, /etc/shadow) correlated with web server process activity.
- Inventory devices running Boa 0.94.14rc21 or embedding wapopen to identify exposed instances.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://pastebin.com/raw/rt7LJvyF | ExploitThird Party Advisory |
| https://www.exploit-db.com/exploits/42290/ | ExploitThird Party AdvisoryVDB Entry |
| https://pastebin.com/raw/rt7LJvyF | ExploitThird Party Advisory |
| https://www.exploit-db.com/exploits/42290/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2017-9833 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-9833), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.