PT-2019-13317 · Advan · Advan Vd-1

Keniver Wang

+2

·

Published

2019-08-29

·

Updated

2020-08-24

·

CVE-2019-13405

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Advan VD-1 firmware version 230
Description A broken access control issue allows an attacker to send a POST request to "cgibin/AdbSetting.cgi" and enable ADB without authentication, potentially leading to the device being used as a relay or for installing mining software.
Recommendations For Advan VD-1 firmware version 230, consider disabling the ADB service until a patch is available to prevent exploitation. Restrict access to the "cgibin/AdbSetting.cgi" endpoint to minimize the risk of unauthorized ADB enablement.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-13405

Affected Products

Advan Vd-1