CVE-2017-15805: Cisco Small Business SA520 Firmware

High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.

Cisco Small Business SA520 and SA540 devices with firmware 2.1.71 and 2.2.0.7 allow ../ directory traversal in scgi-bin/platform.cgi via the thispage parameter, for reading arbitrary files.

Affected products

  • Cisco Small Business SA520 Firmware: version 2.1.71 only; version 2.2.0.7 only
  • Cisco Small Business SA540 Firmware: version 2.1.71 only; version 2.2.0.7 only

Published 2017-10-23. Last modified 2026-06-17.