Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8hp6-w36x-5x7g

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directly access administrative router settings by crafting URLs with a .cgi extension, as demonstrated by /info.cgi and /password.cgi.

An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directly access administrative router settings by crafting URLs with a .cgi extension, as demonstrated by /info.cgi and /password.cgi.

EPSS

Процентиль: 98%
0.50791
Средний

9.8 Critical

CVSS3

Дефекты

CWE-425

Связанные уязвимости

CVSS3: 9.8
nvd
больше 8 лет назад

An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directly access administrative router settings by crafting URLs with a .cgi extension, as demonstrated by /info.cgi and /password.cgi.

EPSS

Процентиль: 98%
0.50791
Средний

9.8 Critical

CVSS3

Дефекты

CWE-425