PT-2017-11792 · Iball · Iball Ib-Wra300N3Gt

CVE-2017-11169

·

Publicado

2017-11-13

·

Atualizado

2024-02-14

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions iBall iB-WRA300N3GT version 1.1.1
Description The issue allows remote authenticated users to obtain root privileges by leveraging a guest, user, or normal account. This is achieved by submitting a modified privilege parameter to the "/form2userconfig.cgi" API endpoint.
Recommendations For version 1.1.1, consider restricting access to the "/form2userconfig.cgi" API endpoint until a patch is available. Additionally, limit the use of guest, user, or normal accounts to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2017-11169

Produtos afetados

Iball Ib-Wra300N3Gt