7.5

CVE-2018-13109

Exploit
All ADB broadband gateways / routers based on the Epicentro platform are affected by an authorization bypass vulnerability where attackers are able to access and manipulate settings within the web interface that are forbidden to end users (e.g., by the ISP). An attacker would be able to enable the TELNET server or other settings as well.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adbglobal ≫ Dv2210 Firmware Version -
   Adbglobal ≫ Dv2210 Version -
Adbglobal ≫ Vv2220 Firmware Version -
   Adbglobal ≫ Vv2220 Version -
Adbglobal ≫ Vv5522 Firmware Version -
   Adbglobal ≫ Vv5522 Version -
Adbglobal ≫ Prg Av4202n Firmware Version -
   Adbglobal ≫ Prg Av4202n Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 35.86% 0.983
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

http://packetstormsecurity.com/files/148429/ADB-Authorization-Bypass.html
Third Party Advisory
VDB Entry
http://seclists.org/fulldisclosure/2018/Jul/18
Third Party Advisory
Mailing List
http://www.securityfocus.com/archive/1/542119/100/0/threaded
Third Party Advisory
VDB Entry
https://www.exploit-db.com/exploits/44982/
Third Party Advisory
VDB Entry
https://www.sec-consult.com/en/blog/advisories/authorization-bypass-in-all-adb-broadband-gateways-routers/
Third Party Advisory
Exploit