CVE-2017-9097 is a local file inclusion (LFI) and arbitrary file write vulnerability in Anti-Web through 3.8.7, affecting NetBiter FGW200 (<=3.21.2), WS100 (<=3.30.5), EC150 (<=1.40.0), WS200 (<=3.30.4), EC250 (<=1.40.0), and other products. The vulnerability allows remote attackers to read or modify files on the device via path traversal, including reading sensitive files such as /etc/passwd or writing arbitrary files using the 'template' parameter in cgi-bin/write.cgi.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a comprehensive exploitation suite for CVE-2017-9097, targeting the Anti-Web server (versions 3.0.x < 3.8.x) used in various industrial/OT products. The suite includes three main Python tools: 1. LFI/anti-web-v1.py: Exploits a Local File Inclusion (LFI) vulnerability via POST requests to /cgi-bin/write.cgi, allowing unauthenticated attackers to read arbitrary files, such as /etc/passwd and /home/config/users.cfg (which contains web credentials). 2. seekAndDestroy/seekAndDestroy.py: Automates extraction and cracking of credentials from the users.cfg file, using a built-in MD5 hash cracker and precomputed hash lists. It can target single hosts or lists of hosts (e.g., from Shodan). 3. RCE/rce.py: Exploits a Remote Command Execution (RCE) vulnerability by uploading and executing a shell script via multipart/form-data POST to /cgi-bin/write.cgi. The output of arbitrary commands is written to a file, which can then be retrieved via LFI. The repository also includes OpenVAS plugin code for detection, extensive documentation, and lists of vulnerable products and IPs. The tools are operational, require minimal configuration, and are effective against unpatched devices. The attack vector is remote network access to the web interface. The suite is not part of a larger framework but is a standalone, weaponized exploit toolkit for industrial control systems.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.