PT-2017-18516 · Unknown · Be126 Wifi Repeater

Hay Mizrachi

+1

·

Published

2017-09-20

·

Updated

2017-09-28

·

CVE-2017-8770

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions BE126 WIFI repeater version 1.0
Description The issue allows attackers to read the entire filesystem on the device. This is achieved by using a crafted getpage parameter, enabling local file disclosure (LFD).
Recommendations For BE126 WIFI repeater version 1.0, avoid using the getpage parameter until a fix is available. As a temporary workaround, consider restricting access to the device to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-8770

Affected Products

Be126 Wifi Repeater