PT-2023-5281 · Unknown · Juplink Rx4-1500

·

CVE-2023-41030

·

Publicado

2023-07-30

·

Atualizado

2023-09-22

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Juplink RX4-1500 versions V1.0.2 through V1.0.5
Description The issue is related to the use of hard-coded credentials in the Juplink RX4-1500 WI-FI router's software. This allows unauthenticated attackers to log in to the web interface or telnet service as the user user, potentially leading to privilege escalation. The exploitation can be done remotely.
Recommendations For Juplink RX4-1500 versions V1.0.2 through V1.0.5, consider changing the default credentials to custom, secure ones to prevent unauthorized access. As a temporary workaround, restrict access to the web interface and telnet service until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-05904
CVE-2023-41030

Produtos afetados

Juplink Rx4-1500