PT-2019-13317 · Advan · Advan Vd-1

Keniver Wang

+2

·

Publicado

2019-08-29

·

Atualizado

2020-08-24

·

CVE-2019-13405

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Advan VD-1 firmware version 230
Description A broken access control issue allows an attacker to send a POST request to "cgibin/AdbSetting.cgi" and enable ADB without authentication, potentially leading to the device being used as a relay or for installing mining software.
Recommendations For Advan VD-1 firmware version 230, consider disabling the ADB service until a patch is available to prevent exploitation. Restrict access to the "cgibin/AdbSetting.cgi" endpoint to minimize the risk of unauthorized ADB enablement.

Exploit

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-13405

Produtos afetados

Advan Vd-1