Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-13405

Опубликовано: 29 авг. 2019
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

A broken access control vulnerability found in Advan VD-1 firmware version 230 leads to insecure ADB service. An attacker can send a POST request to cgibin/AdbSetting.cgi to enable ADB without any authentication then take the compromised device as a relay or to install mining software.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:androvideo:vd_1_firmware:230:*:*:*:*:*:*:*
cpe:2.3:h:androvideo:vd_1:-:*:*:*:*:*:*:*

EPSS

Процентиль: 75%
0.00866
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-306

Связанные уязвимости

github
больше 3 лет назад

A broken access control vulnerability found in Advan VD-1 firmware version 230 leads to insecure ADB service. An attacker can send a POST request to cgibin/AdbSetting.cgi to enable ADB without any authentication then take the compromised device as a relay or to install mining software.

EPSS

Процентиль: 75%
0.00866
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-306