A path traversal vulnerability exists in the Netgear SPH200D Skype phone firmware versions <= 1.0.4.80 in its embedded web server. Authenticated attackers can exploit crafted GET requests to access arbitrary files outside the web root by injecting traversal sequences. This can expose sensitive system files and configuration data.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 06 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Tue, 05 Aug 2025 11:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Netgear Netgear sph200d | |
| Vendors & Products | Netgear Netgear sph200d | 
Fri, 01 Aug 2025 21:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A path traversal vulnerability exists in the Netgear SPH200D Skype phone firmware versions <= 1.0.4.80 in its embedded web server. Authenticated attackers can exploit crafted GET requests to access arbitrary files outside the web root by injecting traversal sequences. This can expose sensitive system files and configuration data. | |
| Title | Netgear SPH200D <= 1.0.4.80 Path Traversal via HTTP GET | |
| Weaknesses | CWE-22 | |
| References |  | 
 | 
| Metrics | cvssV4_0 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-08-01T20:46:21.225Z
Updated: 2025-08-06T14:38:45.793Z
Reserved: 2025-08-01T18:54:27.633Z
Link: CVE-2013-10063
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-08-06T14:38:33.185Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-08-01T21:15:28.677
Modified: 2025-08-06T15:15:31.060
Link: CVE-2013-10063
 Redhat
                        Redhat
                    No data.