Kyocera Command Center RX ECOSYS M2035dn
cpe:2.3:o:kyocera:command_center_rx:*:*:*:*:*:*:*
- ECOSYS M2035dn
A directory traversal vulnerability has been identified in the Kyocera Command Center RX application for the ECOSYS M2035dn model. This vulnerability allows unauthenticated attackers to read sensitive system files by manipulating file paths under the '/js/' directory. Exploitation involves sending crafted requests that traverse the directory structure, appending a null byte to bypass file type restrictions, and accessing critical files such as '/etc/passwd' and '/etc/shadow'.
Exploitation of this vulnerability leads to unauthorized access and disclosure of sensitive system files, including password and shadow files, which can be used for further attacks or privilege escalation.
The vulnerability can be reproduced by sending a GET request to the '/js/' directory with a crafted file path that includes directory traversal sequences (such as '../../..') to navigate up the directory structure. Appending a null byte and a file extension (like '.jpg') can bypass certain file type restrictions, allowing access to sensitive files like '/etc/passwd' and '/etc/shadow'.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.