PT-2018-11234 · Intex · Intex N150

Navina Asrani

·

Publicado

2018-07-02

·

Atualizado

2018-09-05

·

CVE-2018-12528

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:S/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions Intex N150 devices (affected versions not specified)
Description An issue was discovered where the backup/restore option does not check the file extension uploaded for importing configuration files backup. This can lead to corrupting the router firmware settings or the uploading of malicious files. To exploit this, an attacker can upload any malicious file and force reboot the router with it.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-12528

Produtos afetados

Intex N150