PT-2019-10100 · Unknown · Epon Cpe-Wifi

Published

2019-01-03

·

Updated

2019-10-03

·

CVE-2018-20512

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: EPON CPE-WiFi devices version 2.0.4-X000
Description: The issue allows for escalation of privileges. This can be achieved by sending specific cookies, including cooLogin=1, cooUser=admin, and timestamp=-1.
Recommendations: For EPON CPE-WiFi devices version 2.0.4-X000, avoid using the cooLogin, cooUser, and timestamp cookies until the issue is resolved. As a temporary workaround, consider restricting access to administrative functions to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-20512

Affected Products

Epon Cpe-Wifi