.. / CVE-2020-12447

Exploit for Onkyo TX-NR585 Web Interface - Directory Traversal (CVE-2020-12447)

Description:

Onkyo TX-NR585 1000-0000-000-0008-0000 devices allows remote unauthenticated users on the network to read sensitive files via %2e%2e%2f directory traversal and local file inclusion.

Nuclei Template

View the template here CVE-2020-12447.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-12447.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2020-12447
https://blog.spookysec.net/onkyo-lfi/
https://github.com/ARPSyndicate/kenzer-templates
https://blog.spookysec.net/onkyo-lfi