PT-2019-13355 · Busybox+4 · Busybox+12

Benjamin K.M

·

Published

2019-09-11

·

Updated

2023-09-05

·

CVE-2019-13473

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TELESTAR Bobs Rock Radio version (affected versions not specified) Dabman D10 version (affected versions not specified) Dabman i30 Stereo version (affected versions not specified) Imperial i110 version (affected versions not specified) Imperial i150 version (affected versions not specified) Imperial i200 version (affected versions not specified) Imperial i200-cd version (affected versions not specified) Imperial i400 version (affected versions not specified) Imperial i450 version (affected versions not specified) Imperial i500-bt version (affected versions not specified) Imperial i600 TN81HH96-g102h-g102 version (affected versions not specified)
Description The issue is related to an undocumented TELNET service within the BusyBox subsystem, which can lead to root access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2687
ALT-PU-2019-2690
CVE-2019-13473

Affected Products

Alt Linux
Busybox
Dabman D10
Dabman I30 Stereo
Imperial I110
Imperial I150
Imperial I200
Imperial I200-Cd
Imperial I400
Imperial I450
Imperial I500-Bt
Imperial I600 Tn81Hh96-G102H-G102
Telestar Bobs Rock Radio