7.5
CVE-2018-13109
- EPSS 7.34%
- Published 06.07.2018 14:29:01
- Last modified 21.11.2024 03:46:27
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
All ADB broadband gateways / routers based on the Epicentro platform are affected by an authorization bypass vulnerability where attackers are able to access and manipulate settings within the web interface that are forbidden to end users (e.g., by the ISP). An attacker would be able to enable the TELNET server or other settings as well.
Data is provided by the National Vulnerability Database (NVD)
Adbglobal ≫ Dv2210 Firmware Version-
Adbglobal ≫ Vv2220 Firmware Version-
Adbglobal ≫ Vv5522 Firmware Version-
Adbglobal ≫ Prg Av4202n Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 7.34% | 0.913 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.