Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7vw7-45gr-9vpj

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.6

Описание

Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 devices are distributed by some ISPs with a default password of "password" for the admin account that is used over an unencrypted http://192.168.0.1 connection, which might allow remote attackers to bypass intended access restrictions by leveraging access to the local network. NOTE: one or more user's guides distributed by ISPs state "At a minimum, you should set a login password."

Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 devices are distributed by some ISPs with a default password of "password" for the admin account that is used over an unencrypted http://192.168.0.1 connection, which might allow remote attackers to bypass intended access restrictions by leveraging access to the local network. NOTE: one or more user's guides distributed by ISPs state "At a minimum, you should set a login password."

EPSS

Процентиль: 57%
0.00355
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-1188

Связанные уязвимости

CVSS3: 6.6
nvd
больше 7 лет назад

Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 devices are distributed by some ISPs with a default password of "password" for the admin account that is used over an unencrypted http://192.168.0.1 connection, which might allow remote attackers to bypass intended access restrictions by leveraging access to the local network. NOTE: one or more user's guides distributed by ISPs state "At a minimum, you should set a login password."

EPSS

Процентиль: 57%
0.00355
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-1188