NetMechanica NetDecision TFTP Server 4.2 contains multiple directory traversal vulnerabilities in its handling of the GET and PUT commands. Remote attackers can exploit these flaws by including directory traversal sequences (such as '../') in the file path arguments to read or modify arbitrary files on the server, bypassing intended file system restrictions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (Ruby file) that exploits a directory traversal vulnerability (CVE-2009-1730) in NetDecision 4.2 TFTP server running on Windows XP SP3 or Windows 2003 SP2. The exploit works by abusing the TFTP server's lack of path sanitization to upload arbitrary files outside the intended directory, specifically to C:\Windows\System32 and C:\Windows\System32\wbem\mof. The module generates a custom Windows executable payload and a malicious MOF file, uploads both via TFTP, and leverages WMI to execute the payload, resulting in remote code execution under the TFTP server's user context. The main attack vector is network-based, requiring only TFTP access to the vulnerable server. The module is operational and allows for arbitrary code execution, but is not weaponized for mass exploitation. The only file in the repository is the Metasploit exploit module itself.
This repository contains a single Metasploit auxiliary scanner module targeting a directory traversal vulnerability (CVE-2009-1730) in the NetDecision 4.2 TFTP service. The module exploits the vulnerability by sending a crafted TFTP read request containing directory traversal sequences (../) to the target's UDP port 69. This allows the attacker to retrieve arbitrary files from the target system, with the default file being 'windows\win.ini'. The module is written in Ruby and is structured as a standard Metasploit auxiliary module, with options to specify the depth of traversal and the filename to retrieve. The exploit is operational and provides file exfiltration capabilities, saving the retrieved file locally. No fake or detection-only code is present; this is a real exploit module.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.