PT-2007-1988 · Centrality Communications · Pa168

Adrian Pastor

+1

·

Published

2007-01-26

·

Updated

2018-10-16

·

CVE-2007-0528

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Centrality Communications (aka Aredfox) PA168 chipset and firmware versions 1.54 and earlier
Description The issue concerns the admin web console, which does not require passwords or authentication tokens when using HTTP. This allows remote attackers to connect to existing superuser sessions, potentially obtaining sensitive information such as passwords and configuration data.
Recommendations For firmware versions 1.54 and earlier, consider disabling HTTP access to the admin web console until a patch is available. Restrict access to the admin web console to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0528

Affected Products

Pa168