PT-2017-18516 · Unknown · Be126 Wifi Repeater
Hay Mizrachi
+1
·
Published
2017-09-20
·
Updated
2017-09-28
·
CVE-2017-8770
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
BE126 WIFI repeater version 1.0
Description
The issue allows attackers to read the entire filesystem on the device. This is achieved by using a crafted
getpage parameter, enabling local file disclosure (LFD).Recommendations
For BE126 WIFI repeater version 1.0, avoid using the
getpage parameter until a fix is available. As a temporary workaround, consider restricting access to the device to minimize the risk of exploitation.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Be126 Wifi Repeater