PT-2019-18521 · Linksys · Linksys Wrt1900Acs

T0B0Rx0R

·

Publicado

2019-06-06

·

Atualizado

2021-07-21

·

CVE-2019-7311

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linksys WRT1900ACS version 1.0.3.187766
Description The issue concerns a lack of encryption in storing the user login cookie, specifically the admin-auth cookie, which contains the admin password in base64 cleartext. This allows a local attacker to discover the admin password and gain administrative access to the router. An attacker can exploit this by sniffing the network during login or by gaining physical access to the victim's computer soon after an administrative login.
Recommendations For Linksys WRT1900ACS version 1.0.3.187766, consider changing the admin password regularly and avoiding using the same password across multiple devices as a temporary mitigation measure. Restrict access to the router's administrative interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Encryption of Sensitive Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-7311

Produtos afetados

Linksys Wrt1900Acs