Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qv2v-77pv-fhr9

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A broken access control vulnerability found in Advan VD-1 firmware version 230 leads to insecure ADB service. An attacker can send a POST request to cgibin/AdbSetting.cgi to enable ADB without any authentication then take the compromised device as a relay or to install mining software.

A broken access control vulnerability found in Advan VD-1 firmware version 230 leads to insecure ADB service. An attacker can send a POST request to cgibin/AdbSetting.cgi to enable ADB without any authentication then take the compromised device as a relay or to install mining software.

EPSS

Процентиль: 75%
0.00866
Низкий

Связанные уязвимости

CVSS3: 9.8
nvd
больше 6 лет назад

A broken access control vulnerability found in Advan VD-1 firmware version 230 leads to insecure ADB service. An attacker can send a POST request to cgibin/AdbSetting.cgi to enable ADB without any authentication then take the compromised device as a relay or to install mining software.

EPSS

Процентиль: 75%
0.00866
Низкий