PT-2017-18517 · Be · Be126 Wifi Repeater
Published
2017-09-20
·
Updated
2017-09-28
·
CVE-2017-8771
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
BE126 WIFI repeater version 1.0
Description
The issue allows an attacker to log into the device using default credentials as root, with the username:
root and password: root, via telnet, which is open by default. The attacker can then trick a connected user into clicking a malicious link, leading to the infection of the device with malicious code.Recommendations
For BE126 WIFI repeater version 1.0, change the default credentials for the root user to prevent unauthorized access via telnet. As a temporary workaround, consider disabling telnet access until a patch is available. Restrict access to the device to minimize the risk of exploitation.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Be126 Wifi Repeater