PT-2018-17558 · Anchorfree · Hotspot Shield
Paulos Yibelo
·
Published
2018-01-31
·
Updated
2025-11-23
·
CVE-2018-6460
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Hotspot Shield (affected versions not specified)
Description
The issue concerns a web server running on Hotspot Shield with a static IP address and port 895. This web server utilizes JSONP and stores sensitive configuration information. An unauthenticated attacker can exploit this by sending a POST request to the "/status.js" API endpoint with the parameter
func=$ APPLOG.Rfunc, allowing them to extract sensitive machine information. This includes details about the user's VPN connection status, the specific VPN connected to, and the user's real IP address.Recommendations
For Hotspot Shield, consider restricting access to the "/status.js" API endpoint to prevent unauthorized data extraction until a patch is available. As a temporary workaround, disabling the
$ APPLOG.Rfunc parameter in the POST request to "/status.js" may help mitigate the risk of sensitive information disclosure. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hotspot Shield