PT-2013-5343 · Hot · Hotbox Router
Published
2013-12-30
·
Updated
2013-12-30
·
CVE-2013-5038
CVSS v2.0
5.8
Medium
| Vector | AV:A/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
HOT HOTBOX router version 2.1.11
Description
The issue allows remote attackers to bypass authentication by configuring a source IP address that had previously been used for an authenticated session.
Recommendations
For version 2.1.11, consider restricting access to the router's configuration interface to minimize the risk of exploitation. As a temporary workaround, implement additional authentication measures, such as MAC address filtering or VPN, to reduce the attack surface until a patch is available.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hotbox Router