6.5

CVE-2019-13140

Exploit
Inteno EG200 EG200-WU7P1U_ADAMO3.16.4-190226_1650 routers have a JUCI ACL misconfiguration that allows the "user" account to extract the 3DES key via JSON commands to ubus. The 3DES key is used to decrypt the provisioning file provided by Adamo Telecom on a public URL via cleartext HTTP.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IntenogroupEg200 Firmware Versioneg200-wu7p1u_adamo3.16.4-190226_1650
   IntenogroupEg200 Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.04% 0.786
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-552 Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.

http://packetstormsecurity.com/files/154494/Inteno-IOPSYS-Gateway-3DES-Key-Extraction-Improper-Access.html
Third Party Advisory
Exploit
VDB Entry
https://twitter.com/GerardFuguet/status/1169298861782896642
Third Party Advisory
https://www.exploit-db.com/docs/47397
Third Party Advisory
Exploit
VDB Entry
https://www.exploit-db.com/exploits/47390
Third Party Advisory
Exploit
VDB Entry