CVE-2020-7377: RAPID7 Metasploit
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
The Metasploit Framework module "auxiliary/admin/http/telpho10_credential_dump" module is affected by a relative path traversal vulnerability in the untar method which can be exploited to write arbitrary files to arbitrary locations on the host file system when the module is run on a malicious HTTP server.
Affected products
- RAPID7 Metasploit: from 4.12.40, before 6.0.3 (fixed in 6.0.3)
Published 2020-08-24. Last modified 2026-06-17.