PT-2018-6356 · Fiberhome · Fiberhome Lm53Q1

Ibad Shah

·

Publicado

2018-01-12

·

Atualizado

2019-10-03

·

CVE-2017-16885

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: FiberHome LM53Q1 version VH519R05C01S38
Description: The issue is related to improper permissions handling in the portal of the affected device, allowing remote attackers to obtain sensitive information without authentication. This information includes the device version, firmware ID, connected users, and their MAC addresses.
Recommendations: For FiberHome LM53Q1 version VH519R05C01S38, consider restricting access to the portal until a fix is available to prevent unauthorized information disclosure. As a temporary workaround, limit the exposure of the device to the internet or implement additional authentication mechanisms to protect sensitive information.

Exploit

Correção

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-16885

Produtos afetados

Fiberhome Lm53Q1