PT-2018-3327 · Wifiranger · Wifiranger

Published

2018-10-19

·

Updated

2020-08-24

·

CVE-2018-17873

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: WiFiRanger versions 7.0.8rc3 and earlier
Description: The issue is related to an incorrect access control vulnerability in the FTP configuration, which can be exploited by an attacker with adjacent network access to read the SSH Private Key and log in to the root account. This vulnerability is also associated with errors in key management, potentially allowing a remote attacker to gain access to the SSH key and enter the system with a root account.
Recommendations: For WiFiRanger versions 7.0.8rc3 and earlier, consider restricting access to the FTP configuration and SSH Private Key to minimize the risk of exploitation. As a temporary workaround, restrict access to the root account until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04820
CVE-2018-17873

Affected Products

Wifiranger