Bug #17060
closedPath traversal when downloading or deleting files via ``tftp_files.php``
100%
Description
The TFTP package has a Files tab at tftp_files.php that allows administrators to manage files available to TFTP clients. Among other features, this page allows administrators to download or delete files by passing a path and filename.
The package contains an incomplete boundary check that fails to properly restrict the download and delete actions to the TFTP server file directory at /tftpboot. As a consequence, users with access to this page can use directory traversal techniques to download or delete arbitrary files on the device.
Reported by: Rafael Honorato (@honorato0)
JP Updated by Jim Pingle 10 days ago
- Description updated (diff)
JP Updated by Jim Pingle 10 days ago
- Status changed from Confirmed to Feedback
- % Done changed from 0 to 100
Fixed in TFTP pkg version 0.2
CC Updated by Christopher Cope 9 days ago
- Status changed from Feedback to Resolved
Tested on
26.07-RELEASE (amd64) built on Fri Aug 7 19:26:00 UTC 2026 FreeBSD 16.0-CURRENT tfptd 0.2
I can confirm this no longer works and now presents an error message. Marking resolved.
JP Updated by Jim Pingle 7 days ago
- Description updated (diff)
- Private changed from Yes to No
Updated package is available for Plus 26.07 and CE 2.9.0