PT-2018-18615 · Nucom · Nucom Wr644Gacv

Hernán Moller

·

Published

2018-06-25

·

Updated

2019-10-03

·

CVE-2018-8755

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NuCom WR644GACV devices before STA006
Description The issue allows an attacker to download the configuration file without credentials. By doing so, an attacker can access the admin password, WPA key, and any configuration information of the device.
Recommendations For NuCom WR644GACV devices before STA006, update to STA006 or later to resolve the issue. As a temporary workaround, consider restricting access to the device's configuration file until a patch is available.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-8755

Affected Products

Nucom Wr644Gacv