BOA Web Server 0.94.14 is susceptible to arbitrary file access. The server allows the injection of “../..” using the FILECAMERA variable sent by GET to read files with root privileges and without using access credentials.
View the template here CVE-2017-9833.yaml
References:
https://www.exploit-db.com/exploits/42290