PT-2013-6187 · Satech · Satechi Travel Router
Published
2013-11-30
·
Updated
2014-03-05
·
CVE-2013-6918
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Satechi travel router version 1.5
Description
The issue concerns the web interface of the Satechi travel router. When Wi-Fi is used for WAN access, the console is exposed without authentication on the WAN IP address. This exposure occurs regardless of the "Web Management via WAN" setting, allowing remote attackers to bypass intended access restrictions via HTTP requests.
Recommendations
For Satechi travel router version 1.5, as a temporary workaround, consider disabling the web interface when using Wi-Fi for WAN access until a patch is available. Restrict access to the web management interface to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Satechi Travel Router