| |
Vulnerability CVE-2017-7315
Published: 2017-07-03 Modified: 2017-07-04
Description: |
An issue was discovered on Humax Digital HG100R 2.0.6 devices. To download the backup file it's not necessary to use credentials, and the router credentials are stored in plaintext inside the backup, aka GatewaySettings.bin. |
See advisories in our WLB2 database: | Topic | Author | Date |
High |
| gambler | 01.07.2017 |
Low |
| The Gambler | 04.07.2017 |
Type:
CWE-522 (Insufficiently Protected Credentials)
CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
10/10 |
10/10 |
10/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Low |
No required |
Confidentiality impact |
Integrity impact |
Availability impact |
Complete |
Complete |
Complete |
References: |
http://seclists.org/fulldisclosure/2017/Jun/45
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|