PT-2019-16600 · Wifi Soft · Wifi-Soft Unibox Controller
Sahil Dhar
·
Publicado
2019-03-18
·
Atualizado
2021-09-13
·
CVE-2019-3495
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Wifi-soft UniBox controller versions 0.x through 2.x
Description
An issue was discovered that allows for arbitrary file upload through the
network/mesh/edit-nds.php endpoint, enabling an attacker to upload .php files and execute code on the server with root user privileges. The authentication for accessing this component can be bypassed by using hard-coded credentials.Recommendations
For Wifi-soft UniBox controller versions 0.x through 2.x, as a temporary workaround, consider disabling access to the
network/mesh/edit-nds.php endpoint until a patch is available. Restrict the use of hard-coded credentials to minimize the risk of exploitation.Exploit
Correção
Using Hardcoded Credentials
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Wifi-Soft Unibox Controller