PT-2018-6356 · Fiberhome · Fiberhome Lm53Q1

Ibad Shah

·

Published

2018-01-12

·

Updated

2019-10-03

·

CVE-2017-16885

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: FiberHome LM53Q1 version VH519R05C01S38
Description: The issue is related to improper permissions handling in the portal of the affected device, allowing remote attackers to obtain sensitive information without authentication. This information includes the device version, firmware ID, connected users, and their MAC addresses.
Recommendations: For FiberHome LM53Q1 version VH519R05C01S38, consider restricting access to the portal until a fix is available to prevent unauthorized information disclosure. As a temporary workaround, limit the exposure of the device to the internet or implement additional authentication mechanisms to protect sensitive information.

Exploit

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-16885

Affected Products

Fiberhome Lm53Q1