PT-2018-11234 · Intex · Intex N150

Navina Asrani

·

Published

2018-07-02

·

Updated

2018-09-05

·

CVE-2018-12528

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions Intex N150 devices (affected versions not specified)
Description An issue was discovered where the backup/restore option does not check the file extension uploaded for importing configuration files backup. This can lead to corrupting the router firmware settings or the uploading of malicious files. To exploit this, an attacker can upload any malicious file and force reboot the router with it.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-12528

Affected Products

Intex N150